+ if(verbose) {
+ fprintf(stderr, "Could not find Name in %s.\n", tinc_conf);
+ }
+
+ return NULL;
+}
+
+static ecdsa_t *get_pubkey(FILE *f) ATTR_MALLOC ATTR_DEALLOCATOR(ecdsa_free);
+static ecdsa_t *get_pubkey(FILE *f) {
+ char buf[4096];
+ char *value;
+
+ while(fgets(buf, sizeof(buf), f)) {
+ size_t len = strcspn(buf, "\t =");
+ value = buf + len;
+ value += strspn(value, "\t ");
+
+ if(*value == '=') {
+ value++;
+ value += strspn(value, "\t ");
+ }
+
+ if(!rstrip(value)) {
+ continue;
+ }
+
+ buf[len] = 0;
+
+ if(strcasecmp(buf, "Ed25519PublicKey")) {
+ continue;
+ }
+
+ if(*value) {
+ return ecdsa_set_base64_public_key(value);
+ }
+ }
+
+ return NULL;
+}
+
+const var_t variables[] = {
+ /* Server configuration */
+ {"AddressFamily", VAR_SERVER | VAR_SAFE},
+ {"AutoConnect", VAR_SERVER | VAR_SAFE},
+ {"BindToAddress", VAR_SERVER | VAR_MULTIPLE},
+ {"BindToInterface", VAR_SERVER},
+ {"Broadcast", VAR_SERVER | VAR_SAFE},
+ {"BroadcastSubnet", VAR_SERVER | VAR_MULTIPLE | VAR_SAFE},
+ {"ConnectTo", VAR_SERVER | VAR_MULTIPLE | VAR_SAFE},
+ {"DecrementTTL", VAR_SERVER | VAR_SAFE},
+ {"Device", VAR_SERVER},
+ {"DeviceStandby", VAR_SERVER},
+ {"DeviceType", VAR_SERVER},
+ {"DirectOnly", VAR_SERVER | VAR_SAFE},
+ {"Ed25519PrivateKeyFile", VAR_SERVER},
+ {"ExperimentalProtocol", VAR_SERVER},
+ {"Forwarding", VAR_SERVER},
+ {"FWMark", VAR_SERVER},
+ {"GraphDumpFile", VAR_SERVER | VAR_OBSOLETE},
+ {"Hostnames", VAR_SERVER},
+ {"IffOneQueue", VAR_SERVER},
+ {"Interface", VAR_SERVER},
+ {"InvitationExpire", VAR_SERVER},
+ {"KeyExpire", VAR_SERVER | VAR_SAFE},
+ {"ListenAddress", VAR_SERVER | VAR_MULTIPLE},
+ {"LocalDiscovery", VAR_SERVER | VAR_SAFE},
+ {"LogLevel", VAR_SERVER},
+ {"MACExpire", VAR_SERVER | VAR_SAFE},
+ {"MaxConnectionBurst", VAR_SERVER | VAR_SAFE},
+ {"MaxOutputBufferSize", VAR_SERVER | VAR_SAFE},
+ {"MaxTimeout", VAR_SERVER | VAR_SAFE},
+ {"Mode", VAR_SERVER | VAR_SAFE},
+ {"Name", VAR_SERVER},
+ {"PingInterval", VAR_SERVER | VAR_SAFE},
+ {"PingTimeout", VAR_SERVER | VAR_SAFE},
+ {"PriorityInheritance", VAR_SERVER},
+ {"PrivateKey", VAR_SERVER | VAR_OBSOLETE},
+ {"PrivateKeyFile", VAR_SERVER},
+ {"ProcessPriority", VAR_SERVER},
+ {"Proxy", VAR_SERVER},
+ {"ReplayWindow", VAR_SERVER | VAR_SAFE},
+ {"Sandbox", VAR_SERVER},
+ {"ScriptsExtension", VAR_SERVER},
+ {"ScriptsInterpreter", VAR_SERVER},
+ {"StrictSubnets", VAR_SERVER | VAR_SAFE},
+ {"TunnelServer", VAR_SERVER | VAR_SAFE},
+ {"UDPDiscovery", VAR_SERVER | VAR_SAFE},
+ {"UDPDiscoveryKeepaliveInterval", VAR_SERVER | VAR_SAFE},
+ {"UDPDiscoveryInterval", VAR_SERVER | VAR_SAFE},
+ {"UDPDiscoveryTimeout", VAR_SERVER | VAR_SAFE},
+ {"MTUInfoInterval", VAR_SERVER | VAR_SAFE},
+ {"UDPInfoInterval", VAR_SERVER | VAR_SAFE},
+ {"UDPRcvBuf", VAR_SERVER},
+ {"UDPSndBuf", VAR_SERVER},
+ {"UPnP", VAR_SERVER},
+ {"UPnPDiscoverWait", VAR_SERVER},
+ {"UPnPRefreshPeriod", VAR_SERVER},
+ {"VDEGroup", VAR_SERVER},
+ {"VDEPort", VAR_SERVER},
+ /* Host configuration */
+ {"Address", VAR_HOST | VAR_MULTIPLE},
+ {"Cipher", VAR_SERVER | VAR_HOST},
+ {"ClampMSS", VAR_SERVER | VAR_HOST | VAR_SAFE},
+ {"Compression", VAR_SERVER | VAR_HOST | VAR_SAFE},
+ {"Digest", VAR_SERVER | VAR_HOST},
+ {"Ed25519PublicKey", VAR_HOST},
+ {"Ed25519PublicKeyFile", VAR_SERVER | VAR_HOST},
+ {"IndirectData", VAR_SERVER | VAR_HOST | VAR_SAFE},
+ {"MACLength", VAR_SERVER | VAR_HOST},
+ {"PMTU", VAR_SERVER | VAR_HOST},
+ {"PMTUDiscovery", VAR_SERVER | VAR_HOST},
+ {"Port", VAR_HOST},
+ {"PublicKey", VAR_HOST | VAR_OBSOLETE},
+ {"PublicKeyFile", VAR_SERVER | VAR_HOST | VAR_OBSOLETE},
+ {"Subnet", VAR_HOST | VAR_MULTIPLE | VAR_SAFE},
+ {"TCPOnly", VAR_SERVER | VAR_HOST | VAR_SAFE},
+ {"Weight", VAR_HOST | VAR_SAFE},
+ {NULL, 0}
+};
+
+// Request actual port from tincd
+static bool read_actual_port(void) {
+ pidfile_t *pidfile = read_pidfile();
+
+ if(pidfile) {
+ printf("%s\n", pidfile->port);
+ free(pidfile);
+ return true;
+ } else {
+ fprintf(stderr, "Could not get port from the pidfile.\n");
+ return false;
+ }
+}
+
+static int cmd_config(int argc, char *argv[]) {
+ if(argc < 2) {
+ fprintf(stderr, "Invalid number of arguments.\n");
+ return 1;
+ }
+
+ if(strcasecmp(argv[0], "config")) {
+ argv--, argc++;
+ }
+
+ typedef enum { GET, DEL, SET, ADD } action_t;
+ action_t action = GET;
+
+ if(!strcasecmp(argv[1], "get")) {
+ argv++, argc--;
+ } else if(!strcasecmp(argv[1], "add")) {
+ argv++, argc--, action = ADD;
+ } else if(!strcasecmp(argv[1], "del")) {
+ argv++, argc--, action = DEL;
+ } else if(!strcasecmp(argv[1], "replace") || !strcasecmp(argv[1], "set") || !strcasecmp(argv[1], "change")) {
+ argv++, argc--, action = SET;
+ }
+
+ if(argc < 2) {
+ fprintf(stderr, "Invalid number of arguments.\n");
+ return 1;
+ }
+
+ // Concatenate the rest of the command line
+ strncpy(line, argv[1], sizeof(line) - 1);
+
+ for(int i = 2; i < argc; i++) {
+ strncat(line, " ", sizeof(line) - 1 - strlen(line));
+ strncat(line, argv[i], sizeof(line) - 1 - strlen(line));
+ }
+
+ // Liberal parsing into node name, variable name and value.
+ char *node = NULL;
+ char *variable;
+ char *value;
+ size_t len;
+
+ len = strcspn(line, "\t =");
+ value = line + len;
+ value += strspn(value, "\t ");
+
+ if(*value == '=') {
+ value++;
+ value += strspn(value, "\t ");
+ }
+
+ line[len] = '\0';
+ variable = strchr(line, '.');
+
+ if(variable) {
+ node = line;
+ *variable++ = 0;
+ } else {
+ variable = line;
+ }
+
+ if(!*variable) {
+ fprintf(stderr, "No variable given.\n");
+ return 1;
+ }
+
+ if((action == SET || action == ADD) && !*value) {
+ fprintf(stderr, "No value for variable given.\n");
+ return 1;
+ }
+
+ if(action == GET && *value) {
+ action = SET;
+ }
+
+ // If port is requested, try reading it from the pidfile and fall back to configs if that fails
+ if(action == GET && !strcasecmp(variable, "Port") && read_actual_port()) {
+ return 0;
+ }
+
+ /* Some simple checks. */
+ bool found = false;
+ bool warnonremove = false;
+
+ for(int i = 0; variables[i].name; i++) {
+ if(strcasecmp(variables[i].name, variable)) {
+ continue;
+ }
+
+ found = true;
+ variable = (char *)variables[i].name;
+
+ if(!strcasecmp(variable, "Subnet") && *value) {
+ subnet_t s = {0};
+
+ if(!str2net(&s, value)) {
+ fprintf(stderr, "Malformed subnet definition %s\n", value);
+ return 1;
+ }
+
+ if(!subnetcheck(s)) {
+ fprintf(stderr, "Network address and prefix length do not match: %s\n", value);
+ return 1;
+ }
+ }
+
+ /* Discourage use of obsolete variables. */
+
+ if(variables[i].type & VAR_OBSOLETE && (action == SET || action == ADD)) {
+ if(force) {
+ fprintf(stderr, "Warning: %s is an obsolete variable!\n", variable);
+ } else {
+ fprintf(stderr, "%s is an obsolete variable! Use --force to use it anyway.\n", variable);
+ return 1;
+ }
+ }
+
+ /* Don't put server variables in host config files */
+
+ if(node && !(variables[i].type & VAR_HOST) && (action == SET || action == ADD)) {
+ if(force) {
+ fprintf(stderr, "Warning: %s is not a host configuration variable!\n", variable);
+ } else {
+ fprintf(stderr, "%s is not a host configuration variable! Use --force to use it anyway.\n", variable);
+ return 1;
+ }
+ }
+
+ /* Should this go into our own host config file? */
+
+ if(!node && !(variables[i].type & VAR_SERVER)) {
+ node = get_my_name(true);
+
+ if(!node) {
+ return 1;
+ }
+ }
+
+ /* Change "add" into "set" for variables that do not allow multiple occurrences.
+ Turn on warnings when it seems variables might be removed unintentionally. */
+
+ if(action == ADD && !(variables[i].type & VAR_MULTIPLE)) {
+ warnonremove = true;
+ action = SET;
+ } else if(action == SET && (variables[i].type & VAR_MULTIPLE)) {
+ warnonremove = true;
+ }
+
+ break;
+ }
+
+ if(node && !check_id(node)) {
+ fprintf(stderr, "Invalid name for node.\n");
+
+ if(node != line) {
+ free(node);
+ }
+
+ return 1;
+ }
+
+ if(!found) {
+ if(force || action == GET || action == DEL) {
+ fprintf(stderr, "Warning: %s is not a known configuration variable!\n", variable);
+ } else {
+ fprintf(stderr, "%s: is not a known configuration variable! Use --force to use it anyway.\n", variable);
+
+ if(node && node != line) {
+ free(node);
+ }
+
+ return 1;
+ }
+ }
+
+ // Open the right configuration file.
+ char filename[PATH_MAX];
+
+ if(node) {
+ size_t wrote = (size_t)snprintf(filename, sizeof(filename), "%s" SLASH "%s", hosts_dir, node);
+
+ if(node != line) {
+ free(node);
+ node = NULL;
+ }
+
+ if(wrote >= sizeof(filename)) {
+ fprintf(stderr, "Filename too long: %s" SLASH "%s\n", hosts_dir, node);
+ return 1;
+ }
+
+ } else {
+ snprintf(filename, sizeof(filename), "%s", tinc_conf);
+ }
+
+ FILE *f = fopen(filename, "r");
+
+ if(!f) {
+ fprintf(stderr, "Could not open configuration file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+
+ char tmpfile[PATH_MAX];
+ FILE *tf = NULL;
+
+ if(action != GET) {
+ if((size_t)snprintf(tmpfile, sizeof(tmpfile), "%s.config.tmp", filename) >= sizeof(tmpfile)) {
+ fprintf(stderr, "Filename too long: %s.config.tmp\n", filename);
+ return 1;
+ }
+
+ tf = fopen(tmpfile, "w");
+
+ if(!tf) {
+ fprintf(stderr, "Could not open temporary file %s: %s\n", tmpfile, strerror(errno));
+ fclose(f);
+ return 1;
+ }
+ }
+
+ // Copy the file, making modifications on the fly, unless we are just getting a value.
+ char buf1[4096];
+ char buf2[4096];
+ bool set = false;
+ bool removed = false;
+ found = false;
+
+ while(fgets(buf1, sizeof(buf1), f)) {
+ buf1[sizeof(buf1) - 1] = 0;
+ strncpy(buf2, buf1, sizeof(buf2));
+
+ // Parse line in a simple way
+ char *bvalue;
+
+ size_t len = strcspn(buf2, "\t =");
+ bvalue = buf2 + len;
+ bvalue += strspn(bvalue, "\t ");
+
+ if(*bvalue == '=') {
+ bvalue++;
+ bvalue += strspn(bvalue, "\t ");
+ }
+
+ rstrip(bvalue);
+ buf2[len] = '\0';
+
+ // Did it match?
+ if(!strcasecmp(buf2, variable)) {
+ if(action == GET) {
+ found = true;
+ printf("%s\n", bvalue);
+ } else if(action == DEL) {
+ if(!*value || !strcasecmp(bvalue, value)) {
+ removed = true;
+ continue;
+ }
+ } else if(action == SET) {
+ // Warn if "set" was used for variables that can occur multiple times
+ if(warnonremove && strcasecmp(bvalue, value)) {
+ fprintf(stderr, "Warning: removing %s = %s\n", variable, bvalue);
+ }
+
+ // Already set? Delete the rest...
+ if(set) {
+ continue;
+ }
+
+ // Otherwise, replace.
+ if(fprintf(tf, "%s = %s\n", variable, value) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+
+ set = true;
+ continue;
+ } else if(action == ADD) {
+ // Check if we've already seen this variable with the same value
+ if(!strcasecmp(bvalue, value)) {
+ found = true;
+ }
+ }
+ }
+
+ if(action != GET) {
+ // Copy original line...
+ if(fputs(buf1, tf) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+
+ // Add newline if it is missing...
+ if(*buf1 && buf1[strlen(buf1) - 1] != '\n') {
+ if(fputc('\n', tf) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+ }
+ }
+ }
+
+ // Make sure we read everything...
+ if(ferror(f) || !feof(f)) {
+ fprintf(stderr, "Error while reading from configuration file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+
+ if(fclose(f)) {
+ fprintf(stderr, "Error closing configuration file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+
+ // Add new variable if necessary.
+ if((action == ADD && !found) || (action == SET && !set)) {
+ if(fprintf(tf, "%s = %s\n", variable, value) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+ }
+
+ if(action == GET) {
+ if(found) {
+ return 0;
+ } else {
+ fprintf(stderr, "No matching configuration variables found.\n");
+ return 1;
+ }
+ }
+
+ // Make sure we wrote everything...
+ if(fclose(tf)) {
+ fprintf(stderr, "Error closing temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+
+ // Could we find what we had to remove?
+ if((action == GET || action == DEL) && !removed) {
+ remove(tmpfile);
+ fprintf(stderr, "No configuration variables deleted.\n");
+ return 1;
+ }
+
+ // Replace the configuration file with the new one
+#ifdef HAVE_WINDOWS
+
+ if(remove(filename)) {
+ fprintf(stderr, "Error replacing file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+
+#endif
+
+ if(rename(tmpfile, filename)) {
+ fprintf(stderr, "Error renaming temporary file %s to configuration file %s: %s\n", tmpfile, filename, strerror(errno));
+ return 1;
+ }
+
+ // Silently try notifying a running tincd of changes.
+ if(connect_tincd(false)) {
+ sendline(fd, "%d %d", CONTROL, REQ_RELOAD);
+ }
+
+ return 0;
+}
+
+static bool try_bind(int port) {
+ struct addrinfo *ai = NULL, *aip;
+ struct addrinfo hint = {
+ .ai_flags = AI_PASSIVE,
+ .ai_family = AF_UNSPEC,
+ .ai_socktype = SOCK_STREAM,
+ .ai_protocol = IPPROTO_TCP,
+ };
+
+ bool success = true;
+ char portstr[16];
+ snprintf(portstr, sizeof(portstr), "%d", port);
+
+ if(getaddrinfo(NULL, portstr, &hint, &ai) || !ai) {
+ return false;
+ }
+
+ for(aip = ai; aip; aip = aip->ai_next) {
+ int fd = socket(ai->ai_family, SOCK_STREAM, IPPROTO_TCP);
+
+ if(!fd) {
+ success = false;
+ break;
+ }
+
+ int result = bind(fd, ai->ai_addr, ai->ai_addrlen);
+ closesocket(fd);
+
+ if(result) {
+ success = false;
+ break;
+ }
+ }
+
+ freeaddrinfo(ai);
+ return success;
+}
+
+int check_port(const char *name) {
+ if(try_bind(655)) {
+ return 655;
+ }
+
+ fprintf(stderr, "Warning: could not bind to port 655. ");
+
+ for(int i = 0; i < 100; i++) {
+ uint16_t port = 0x1000 + prng(0x8000);
+
+ if(try_bind(port)) {
+ char filename[PATH_MAX];
+ snprintf(filename, sizeof(filename), "%s" SLASH "hosts" SLASH "%s", confbase, name);
+ FILE *f = fopen(filename, "a");
+
+ if(!f) {
+ fprintf(stderr, "Could not open %s: %s\n", filename, strerror(errno));
+ fprintf(stderr, "Please change tinc's Port manually.\n");
+ return 0;
+ }
+
+ fprintf(f, "Port = %d\n", port);
+ fclose(f);
+ fprintf(stderr, "Tinc will instead listen on port %d.\n", port);
+ return port;
+ }
+ }
+
+ fprintf(stderr, "Please change tinc's Port manually.\n");
+ return 0;
+}
+
+static int cmd_init(int argc, char *argv[]) {
+ if(!access(tinc_conf, F_OK)) {
+ fprintf(stderr, "Configuration file %s already exists!\n", tinc_conf);
+ return 1;
+ }
+
+ if(argc > 2) {
+ fprintf(stderr, "Too many arguments!\n");
+ return 1;
+ } else if(argc < 2) {
+ if(tty) {
+ char buf[1024];
+ fprintf(stderr, "Enter the Name you want your tinc node to have: ");
+
+ if(!fgets(buf, sizeof(buf), stdin)) {
+ fprintf(stderr, "Error while reading stdin: %s\n", strerror(errno));
+ return 1;
+ }
+
+ size_t len = rstrip(buf);
+
+ if(!len) {
+ fprintf(stderr, "No name given!\n");
+ return 1;
+ }
+
+ name = strdup(buf);
+ } else {
+ fprintf(stderr, "No Name given!\n");
+ return 1;
+ }
+ } else {
+ name = strdup(argv[1]);
+
+ if(!*name) {
+ fprintf(stderr, "No Name given!\n");
+ return 1;
+ }
+ }
+
+ if(!check_id(name)) {
+ fprintf(stderr, "Invalid Name! Only a-z, A-Z, 0-9 and _ are allowed characters.\n");
+ return 1;
+ }
+
+ if(!makedirs(DIR_HOSTS | DIR_CONFBASE | DIR_CONFDIR | DIR_CACHE)) {