/*
conf.c -- configuration code
Copyright (C) 1998 Robert van der Meulen
- 1998-2001 Ivo Timmermans <itimmermans@bigfoot.com>
- 2000,2001 Guus Sliepen <guus@sliepen.warande.net>
+ 1998-2002 Ivo Timmermans <ivo@o2w.nl>
+ 2000-2002 Guus Sliepen <guus@sliepen.eu.org>
2000 Cris van Pelt <tribbel@arise.dhs.org>
This program is free software; you can redistribute it and/or modify
along with this program; if not, write to the Free Software
Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
- $Id: conf.c,v 1.9.4.47 2001/10/31 20:07:17 guus Exp $
+ $Id: conf.c,v 1.9.4.57 2002/06/21 10:11:12 guus Exp $
*/
#include "config.h"
#include <avl_tree.h>
#include "conf.h"
-#include "netutl.h" /* for strtoip */
+#include "netutl.h" /* for str2address */
#include "system.h"
avl_tree_t *config_tree;
int debug_lvl = 0;
-int timeout = 0; /* seconds before timeout */
+int pingtimeout = 0; /* seconds before timeout */
char *confbase = NULL; /* directory in which all config files are */
char *netname = NULL; /* name of the vpn network */
-/* Will be set if HUP signal is received. It will be processed when it is safe. */
-int sighup = 0;
-
int config_compare(config_t *a, config_t *b)
{
int result;
-
- result = strcmp(a->variable, b->variable);
-
+
+ result = strcasecmp(a->variable, b->variable);
+
if(result)
return result;
result = a->line - b->line;
-
+
if(result)
return result;
else
config_t *cfg;
cp
cfg = (config_t *)xmalloc_and_zero(sizeof(*cfg));
-
+
return cfg;
}
if(!found)
return NULL;
-
- if(strcmp(found->variable, variable))
+
+ if(strcasecmp(found->variable, variable))
return NULL;
return found;
config_t *found;
cp
node = avl_search_node(config_tree, cfg);
-
+
if(node)
{
if(node->next)
{
found = (config_t *)node->next->data;
- if(!strcmp(found->variable, cfg->variable))
+ if(!strcasecmp(found->variable, cfg->variable))
return found;
}
}
-
+
return NULL;
}
-
+
int get_config_bool(config_t *cfg, int *result)
{
cp
*result = 1;
return 1;
}
- else if(!strcasecmp(cfg->value, "np"))
+ else if(!strcasecmp(cfg->value, "no"))
{
*result = 0;
return 1;
if(sscanf(cfg->value, "%d", result) == 1)
return 1;
-
+
syslog(LOG_ERR, _("Integer expected for configuration variable %s in %s line %d"),
cfg->variable, cfg->file, cfg->line);
return 0;
if(!cfg)
return 0;
- *result = cfg->value;
+ *result = xstrdup(cfg->value);
return 1;
}
-int get_config_ip(config_t *cfg, ip_mask_t **result)
+int get_config_address(config_t *cfg, struct addrinfo **result)
{
- ip_mask_t *ip;
+ struct addrinfo *ai;
cp
if(!cfg)
return 0;
- ip = strtoip(cfg->value);
+ ai = str2addrinfo(cfg->value, NULL, 0);
- if(ip)
+ if(ai)
{
- *result = ip;
+ *result = ai;
return 1;
}
- syslog(LOG_ERR, _("IP address expected for configuration variable %s in %s line %d"),
+ syslog(LOG_ERR, _("Hostname or IP address expected for configuration variable %s in %s line %d"),
cfg->variable, cfg->file, cfg->line);
return 0;
}
return 0;
if(sscanf(cfg->value, "%hu", result) == 1)
- return 1;
-
+ {
+ *result = htons(*result);
+ return 1;
+ }
+
syslog(LOG_ERR, _("Port number expected for configuration variable %s in %s line %d"),
cfg->variable, cfg->file, cfg->line);
return 0;
int get_config_subnet(config_t *cfg, subnet_t **result)
{
- ip_mask_t *ip;
subnet_t *subnet;
cp
if(!cfg)
return 0;
- ip = strtoip(cfg->value);
+ subnet = str2net(cfg->value);
- if(!ip)
+ if(!subnet)
{
- syslog(LOG_ERR, _("IP address expected for configuration variable %s in %s line %d"),
+ syslog(LOG_ERR, _("Subnet expected for configuration variable %s in %s line %d"),
cfg->variable, cfg->file, cfg->line);
return 0;
}
-
+
/* Teach newbies what subnets are... */
- if((ip->address & ip->mask) != ip->address)
+ if(((subnet->type == SUBNET_IPV4) && maskcheck(&subnet->net.ipv4.address, subnet->net.ipv4.prefixlength, sizeof(ipv4_t)))
+ || ((subnet->type == SUBNET_IPV6) && maskcheck(&subnet->net.ipv6.address, subnet->net.ipv6.prefixlength, sizeof(ipv6_t))))
{
- syslog(LOG_ERR, _("Network address and subnet mask for configuration variable %s in %s line %d"),
+ syslog(LOG_ERR, _("Network address and prefix length do not match for configuration variable %s in %s line %d"),
cfg->variable, cfg->file, cfg->line);
- free(ip);
+ free(subnet);
return 0;
}
- subnet = new_subnet();
- subnet->type = SUBNET_IPV4;
- subnet->net.ipv4.address = ip->address;
- subnet->net.ipv4.mask = ip->mask;
-
- free(ip);
-
*result = subnet;
-
+
return 1;
}
Read exactly one line and strip the trailing newline if any. If the
file was on EOF, return NULL. Otherwise, return all the data in a
dynamically allocated buffer.
-
+
If line is non-NULL, it will be used as an initial buffer, to avoid
unnecessary mallocing each time this function is called. If buf is
given, and buf needs to be expanded, the var pointed to by buflen
int lineno = 0, ignore = 0;
config_t *cfg;
size_t bufsize;
-
+
cp
if((fp = fopen (fname, "r")) == NULL)
{
- syslog(LOG_ERR, _("Cannot open config file %s: %m"), fname);
+ syslog(LOG_ERR, _("Cannot open config file %s: %s"), fname, strerror(errno));
return -3;
}
bufsize = 100;
buffer = xmalloc(bufsize);
-
+
for(;;)
{
if((line = readline(fp, &buffer, &bufsize)) == NULL)
if(!strcmp(variable, "-----BEGIN"))
ignore = 1;
-
+
if(!ignore)
{
if(((value = strtok(NULL, "\t\n\r =")) == NULL) || value[0] == '#')
x = read_config_file(config_tree, fname);
if(x == -1) /* System error: complain */
{
- syslog(LOG_ERR, _("Failed to read `%s': %m"),
- fname);
+ syslog(LOG_ERR, _("Failed to read `%s': %s"), fname, strerror(errno));
}
free(fname);
cp
- return x;
+ return x;
}
int isadir(const char* f)
}
p = strrchr(file, '/');
-
+
if(p == file) /* It's in the root */
p++;
-
+
x = *p;
*p = '\0';
check1:
if(lstat(f, &s) < 0)
{
- syslog(LOG_ERR, _("Couldn't stat `%s': %m"),
- f);
+ syslog(LOG_ERR, _("Couldn't stat `%s': %s"), f, strerror(errno));
return 0;
}
if(readlink(f, l, MAXBUFSIZE) < 0)
{
- syslog(LOG_ERR, _("Unable to read symbolic link `%s': %m"), f);
+ syslog(LOG_ERR, _("Unable to read symbolic link `%s': %s"), f, strerror(errno));
return 0;
}
-
+
f = l;
goto check1;
}
*p = x;
f = file;
-
+
check2:
if(lstat(f, &s) < 0 && errno != ENOENT)
{
- syslog(LOG_ERR, _("Couldn't stat `%s': %m"),
- f);
+ syslog(LOG_ERR, _("Couldn't stat `%s': %s"), f, strerror(errno));
return 0;
}
-
+
if(errno == ENOENT)
return 1;
if(readlink(f, l, MAXBUFSIZE) < 0)
{
- syslog(LOG_ERR, _("Unable to read symbolic link `%s': %m"), f);
+ syslog(LOG_ERR, _("Unable to read symbolic link `%s': %s"), f, strerror(errno));
return 0;
}
-
+
f = l;
goto check2;
}
f);
return 0;
}
-
+
return 1;
}
{
/* The directory is a relative path or a filename. */
char *p;
-
+
directory = get_current_dir_name();
asprintf(&p, "%s/%s", directory, fn);
free(fn);
}
umask(0077); /* Disallow everything for group and other */
-
+
/* Open it first to keep the inode busy */
if((r = fopen(fn, mode)) == NULL)
{
free(fn);
return NULL;
}
-
+
/* Then check the file for nasty attacks */
if(!is_safe_path(fn)) /* Do not permit any directories that are
readable or writeable by other users. */