along with this program; if not, write to the Free Software
Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
- $Id: net_socket.c,v 1.1.2.30 2003/07/22 20:55:20 guus Exp $
+ $Id: net_socket.c,v 1.1.2.38 2003/12/22 11:04:16 guus Exp $
*/
#include "system.h"
+#include <gnutls/gnutls.h>
+
#include "avl_tree.h"
#include "conf.h"
#include "connection.h"
#include "utils.h"
#include "xalloc.h"
+#ifdef WSAEINPROGRESS
+#define EINPROGRESS WSAEINPROGRESS
+#endif
+
int addressfamily = AF_UNSPEC;
int maxtimeout = 900;
int seconds_till_retry = 5;
listen_socket_t listen_socket[MAXSOCKETS];
int listen_sockets;
+int certselfunc(gnutls_session session, const gnutls_datum *client_cert, int ncerts, const gnutls_datum* req_ca_cert, int nreqs) {
+ logger(LOG_DEBUG, "Client certificate select function called with %d certs, %d requests\n", ncerts, nreqs);
+ return 0;
+}
+
+int scertselfunc(gnutls_session session, const gnutls_datum *server_cert, int ncerts) {
+ logger(LOG_DEBUG, "Server certificate select function called with %d certs\n", ncerts);
+ return 0;
+}
+
/* Setup sockets */
-int setup_listen_socket(sockaddr_t *sa)
+int setup_listen_socket(const sockaddr_t *sa)
{
- int nfd, flags;
+ int nfd;
char *addrstr;
int option;
char *iface;
- struct ifreq ifr;
cp();
nfd = socket(sa->sa.sa_family, SOCK_STREAM, IPPROTO_TCP);
if(nfd < 0) {
- logger(LOG_ERR, _("Creating metasocket failed: %s"), strerror(errno));
+ ifdebug(STATUS) logger(LOG_ERR, _("Creating metasocket failed: %s"), strerror(errno));
return -1;
}
- flags = fcntl(nfd, F_GETFL);
+#ifdef O_NONBLOCK
+ {
+ int flags = fcntl(nfd, F_GETFL);
- if(fcntl(nfd, F_SETFL, flags | O_NONBLOCK) < 0) {
- close(nfd);
- logger(LOG_ERR, _("System call `%s' failed: %s"), "fcntl",
- strerror(errno));
- return -1;
+ if(fcntl(nfd, F_SETFL, flags | O_NONBLOCK) < 0) {
+ closesocket(nfd);
+ logger(LOG_ERR, _("System call `%s' failed: %s"), "fcntl",
+ strerror(errno));
+ return -1;
+ }
}
+#endif
/* Optimize TCP settings */
if(get_config_string
(lookup_config(config_tree, "BindToInterface"), &iface)) {
#if defined(SOL_SOCKET) && defined(SO_BINDTODEVICE)
+ struct ifreq ifr;
+
memset(&ifr, 0, sizeof(ifr));
strncpy(ifr.ifr_ifrn.ifrn_name, iface, IFNAMSIZ);
if(setsockopt(nfd, SOL_SOCKET, SO_BINDTODEVICE, &ifr, sizeof(ifr))) {
- close(nfd);
+ closesocket(nfd);
logger(LOG_ERR, _("Can't bind to interface %s: %s"), iface,
strerror(errno));
return -1;
}
if(bind(nfd, &sa->sa, SALEN(sa->sa))) {
- close(nfd);
+ closesocket(nfd);
addrstr = sockaddr2hostname(sa);
logger(LOG_ERR, _("Can't bind to %s/tcp: %s"), addrstr,
strerror(errno));
}
if(listen(nfd, 3)) {
- close(nfd);
+ closesocket(nfd);
logger(LOG_ERR, _("System call `%s' failed: %s"), "listen",
strerror(errno));
return -1;
return nfd;
}
-int setup_vpn_in_socket(sockaddr_t *sa)
+int setup_vpn_in_socket(const sockaddr_t *sa)
{
- int nfd, flags;
+ int nfd;
char *addrstr;
int option;
-#if defined(SOL_SOCKET) && defined(SO_BINDTODEVICE)
- char *iface;
- struct ifreq ifr;
-#endif
cp();
return -1;
}
- flags = fcntl(nfd, F_GETFL);
- if(fcntl(nfd, F_SETFL, flags | O_NONBLOCK) < 0) {
- close(nfd);
- logger(LOG_ERR, _("System call `%s' failed: %s"), "fcntl",
- strerror(errno));
- return -1;
+#ifdef O_NONBLOCK
+ {
+ int flags = fcntl(nfd, F_GETFL);
+
+ if(fcntl(nfd, F_SETFL, flags | O_NONBLOCK) < 0) {
+ closesocket(nfd);
+ logger(LOG_ERR, _("System call `%s' failed: %s"), "fcntl",
+ strerror(errno));
+ return -1;
+ }
}
+#endif
option = 1;
setsockopt(nfd, SOL_SOCKET, SO_REUSEADDR, &option, sizeof(option));
-#if defined(SOL_SOCKET) && defined(SO_BINDTODEVICE)
- if(get_config_string
- (lookup_config(config_tree, "BindToInterface"), &iface)) {
- memset(&ifr, 0, sizeof(ifr));
- strncpy(ifr.ifr_ifrn.ifrn_name, iface, IFNAMSIZ);
+#if defined(SOL_IP) && defined(IP_MTU_DISCOVER) && defined(IP_PMTUDISC_DO)
+ {
+ bool choice;
- if(setsockopt(nfd, SOL_SOCKET, SO_BINDTODEVICE, &ifr, sizeof(ifr))) {
- close(nfd);
- logger(LOG_ERR, _("Can't bind to interface %s: %s"), iface,
- strerror(errno));
- return -1;
+ if(get_config_bool(lookup_config(myself->connection->config_tree, "PMTUDiscovery"), &choice) && choice) {
+ option = IP_PMTUDISC_DO;
+ setsockopt(nfd, SOL_IP, IP_MTU_DISCOVER, &option, sizeof(option));
+ }
+ }
+#endif
+
+#if defined(SOL_IPV6) && defined(IPV6_MTU_DISCOVER) && defined(IPV6_PMTUDISC_DO)
+ {
+ bool choice;
+
+ if(get_config_bool(lookup_config(myself->connection->config_tree, "PMTUDiscovery"), &choice) && choice) {
+ option = IPV6_PMTUDISC_DO;
+ setsockopt(nfd, SOL_IPV6, IPV6_MTU_DISCOVER, &option, sizeof(option));
+ }
+ }
+#endif
+
+#if defined(SOL_SOCKET) && defined(SO_BINDTODEVICE)
+ {
+ char *iface;
+ struct ifreq ifr;
+
+ if(get_config_string(lookup_config(config_tree, "BindToInterface"), &iface)) {
+ memset(&ifr, 0, sizeof(ifr));
+ strncpy(ifr.ifr_ifrn.ifrn_name, iface, IFNAMSIZ);
+
+ if(setsockopt(nfd, SOL_SOCKET, SO_BINDTODEVICE, &ifr, sizeof(ifr))) {
+ closesocket(nfd);
+ logger(LOG_ERR, _("Can't bind to interface %s: %s"), iface,
+ strerror(errno));
+ return -1;
+ }
}
}
#endif
if(bind(nfd, &sa->sa, SALEN(sa->sa))) {
- close(nfd);
+ closesocket(nfd);
addrstr = sockaddr2hostname(sa);
logger(LOG_ERR, _("Can't bind to %s/udp: %s"), addrstr,
strerror(errno));
void finish_connecting(connection_t *c)
{
+ int result;
+
cp();
ifdebug(CONNECTIONS) logger(LOG_INFO, _("Connected to %s (%s)"), c->name, c->hostname);
c->last_ping_time = now;
- send_id(c);
+ gnutls_init(&c->session, GNUTLS_SERVER);
+ gnutls_set_default_priority(c->session);
+ gnutls_credentials_set(c->session, GNUTLS_CRD_CERTIFICATE, myself->connection->credentials);
+ gnutls_certificate_server_set_request(c->session, GNUTLS_CERT_REQUEST);
+// gnutls_certificate_client_set_select_function(c->session, certselfunc);
+// gnutls_certificate_server_set_select_function(c->session, scertselfunc);
+ gnutls_transport_set_ptr(c->session, c->socket);
}
void do_outgoing_connection(connection_t *c)
goto begin;
}
- memcpy(&c->address, c->outgoing->aip->ai_addr,
- c->outgoing->aip->ai_addrlen);
+ memcpy(&c->address, c->outgoing->aip->ai_addr, c->outgoing->aip->ai_addrlen);
c->outgoing->aip = c->outgoing->aip->ai_next;
if(c->hostname)
/* Non-blocking */
+#ifdef O_NONBLOCK
flags = fcntl(c->socket, F_GETFL);
if(fcntl(c->socket, F_SETFL, flags | O_NONBLOCK) < 0) {
logger(LOG_ERR, _("fcntl for %s: %s"), c->hostname, strerror(errno));
}
+#endif
/* Connect */
return;
}
- close(c->socket);
+ closesocket(c->socket);
ifdebug(CONNECTIONS) logger(LOG_ERR, _("%s: %s"), c->hostname, strerror(errno));
goto begin;
}
+ logger(LOG_DEBUG, _("finishing connection"));
finish_connecting(c);
return;
c = new_connection();
c->name = xstrdup(outgoing->name);
- c->outcipher = myself->connection->outcipher;
- c->outdigest = myself->connection->outdigest;
- c->outmaclength = myself->connection->outmaclength;
- c->outcompression = myself->connection->outcompression;
init_configuration(&c->config_tree);
read_connection_config(c);
connection_t *c;
sockaddr_t sa;
int fd, len = sizeof(sa);
+ int result;
cp();
return false;
}
+#ifdef O_NONBLOCK
+ {
+ int flags = fcntl(fd, F_GETFL);
+
+ if(fcntl(fd, F_SETFL, flags | O_NONBLOCK) < 0) {
+ closesocket(fd);
+ logger(LOG_ERR, _("System call `%s' failed: %s"), "fcntl",
+ strerror(errno));
+ return -1;
+ }
+ }
+#endif
+
sockaddrunmap(&sa);
c = new_connection();
- c->outcipher = myself->connection->outcipher;
- c->outdigest = myself->connection->outdigest;
- c->outmaclength = myself->connection->outmaclength;
- c->outcompression = myself->connection->outcompression;
c->address = sa;
c->hostname = sockaddr2hostname(&sa);
connection_add(c);
c->allow_request = ID;
- send_id(c);
+ gnutls_init(&c->session, GNUTLS_CLIENT);
+ gnutls_set_default_priority(c->session);
+ gnutls_credentials_set(c->session, GNUTLS_CRD_CERTIFICATE, myself->connection->credentials);
+ gnutls_certificate_server_set_request(c->session, GNUTLS_CERT_REQUEST);
+// gnutls_certificate_client_set_select_function(c->session, certselfunc);
+// gnutls_certificate_server_set_select_function(c->session, scertselfunc);
+ gnutls_transport_set_ptr(c->session, c->socket);
+ gnutls_handshake(c->session);
return true;
}