projects
/
tinc
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Enable and fix many extra warnings supported by GCC and Clang.
[tinc]
/
src
/
meta.c
diff --git
a/src/meta.c
b/src/meta.c
index
a05c7bd
..
6a217d6
100644
(file)
--- a/
src/meta.c
+++ b/
src/meta.c
@@
-1,6
+1,6
@@
/*
meta.c -- handle the meta communication
/*
meta.c -- handle the meta communication
- Copyright (C) 2000-201
4
Guus Sliepen <guus@tinc-vpn.org>,
+ Copyright (C) 2000-201
8
Guus Sliepen <guus@tinc-vpn.org>,
2000-2005 Ivo Timmermans
2006 Scott Lamb <slamb@slamb.org>
2000-2005 Ivo Timmermans
2006 Scott Lamb <slamb@slamb.org>
@@
-28,9
+28,15
@@
#include "net.h"
#include "protocol.h"
#include "utils.h"
#include "net.h"
#include "protocol.h"
#include "utils.h"
-#include "xalloc.h"
+
+#ifndef MIN
+static ssize_t MIN(ssize_t x, ssize_t y) {
+ return x < y ? x : y;
+}
+#endif
bool send_meta_sptps(void *handle, uint8_t type, const void *buffer, size_t length) {
bool send_meta_sptps(void *handle, uint8_t type, const void *buffer, size_t length) {
+ (void)type;
connection_t *c = handle;
if(!c) {
connection_t *c = handle;
if(!c) {
@@
-44,30
+50,40
@@
bool send_meta_sptps(void *handle, uint8_t type, const void *buffer, size_t leng
return true;
}
return true;
}
-bool send_meta(connection_t *c, const
char *buffer, in
t length) {
+bool send_meta(connection_t *c, const
void *buffer, size_
t length) {
if(!c) {
logger(DEBUG_ALWAYS, LOG_ERR, "send_meta() called with NULL pointer!");
abort();
}
if(!c) {
logger(DEBUG_ALWAYS, LOG_ERR, "send_meta() called with NULL pointer!");
abort();
}
- logger(DEBUG_META, LOG_DEBUG, "Sending %
d bytes of metadata to %s (%s)", length
,
-
c->name, c->hostname);
+ logger(DEBUG_META, LOG_DEBUG, "Sending %
lu bytes of metadata to %s (%s)"
,
+
(unsigned long)length,
c->name, c->hostname);
- if(c->protocol_minor >= 2)
+ if(c->protocol_minor >= 2)
{
return sptps_send_record(&c->sptps, 0, buffer, length);
return sptps_send_record(&c->sptps, 0, buffer, length);
+ }
/* Add our data to buffer */
if(c->status.encryptout) {
#ifdef DISABLE_LEGACY
return false;
#else
/* Add our data to buffer */
if(c->status.encryptout) {
#ifdef DISABLE_LEGACY
return false;
#else
+
+ if(length > c->outbudget) {
+ logger(DEBUG_META, LOG_ERR, "Byte limit exceeded for encryption to %s (%s)", c->name, c->hostname);
+ return false;
+ } else {
+ c->outbudget -= length;
+ }
+
size_t outlen = length;
size_t outlen = length;
- if(!cipher_encrypt(c->outcipher, buffer, length, buffer_prepare(&c->outbuf, length), &outlen, false) || outlen != length) {
+ if(!cipher_encrypt(
&
c->outcipher, buffer, length, buffer_prepare(&c->outbuf, length), &outlen, false) || outlen != length) {
logger(DEBUG_ALWAYS, LOG_ERR, "Error while encrypting metadata to %s (%s)",
logger(DEBUG_ALWAYS, LOG_ERR, "Error while encrypting metadata to %s (%s)",
-
c->name, c->hostname);
+ c->name, c->hostname);
return false;
}
return false;
}
+
#endif
} else {
buffer_add(&c->outbuf, buffer, length);
#endif
} else {
buffer_add(&c->outbuf, buffer, length);
@@
-78,24
+94,25
@@
bool send_meta(connection_t *c, const char *buffer, int length) {
return true;
}
return true;
}
-void send_meta_raw(connection_t *c, const
char *buffer, in
t length) {
+void send_meta_raw(connection_t *c, const
void *buffer, size_
t length) {
if(!c) {
logger(DEBUG_ALWAYS, LOG_ERR, "send_meta() called with NULL pointer!");
abort();
}
if(!c) {
logger(DEBUG_ALWAYS, LOG_ERR, "send_meta() called with NULL pointer!");
abort();
}
- logger(DEBUG_META, LOG_DEBUG, "Sending %
d bytes of raw metadata to %s (%s)", length
,
-
c->name, c->hostname);
+ logger(DEBUG_META, LOG_DEBUG, "Sending %
lu bytes of raw metadata to %s (%s)"
,
+
(unsigned long)length,
c->name, c->hostname);
buffer_add(&c->outbuf, buffer, length);
io_set(&c->io, IO_READ | IO_WRITE);
}
buffer_add(&c->outbuf, buffer, length);
io_set(&c->io, IO_READ | IO_WRITE);
}
-void broadcast_meta(connection_t *from, const char *buffer,
in
t length) {
- for list_each(connection_t, c, connection_list)
- if(c != from && c->edge)
+void broadcast_meta(connection_t *from, const char *buffer,
size_
t length) {
+ for list_each(connection_t, c,
&
connection_list)
+ if(c != from && c->edge)
{
send_meta(c, buffer, length);
send_meta(c, buffer, length);
+ }
}
bool receive_meta_sptps(void *handle, uint8_t type, const void *vdata, uint16_t length) {
}
bool receive_meta_sptps(void *handle, uint8_t type, const void *vdata, uint16_t length) {
@@
-108,20
+125,24
@@
bool receive_meta_sptps(void *handle, uint8_t type, const void *vdata, uint16_t
}
if(type == SPTPS_HANDSHAKE) {
}
if(type == SPTPS_HANDSHAKE) {
- if(c->allow_request == ACK)
+ if(c->allow_request == ACK)
{
return send_ack(c);
return send_ack(c);
- else
+ } else {
return true;
return true;
+ }
}
}
- if(!data)
+ if(!data)
{
return true;
return true;
+ }
/* Are we receiving a TCPpacket? */
if(c->tcplen) {
/* Are we receiving a TCPpacket? */
if(c->tcplen) {
- if(length != c->tcplen)
+ if(length != c->tcplen)
{
return false;
return false;
+ }
+
receive_tcppacket(c, data, length);
c->tcplen = 0;
return true;
receive_tcppacket(c, data, length);
c->tcplen = 0;
return true;
@@
-129,8
+150,9
@@
bool receive_meta_sptps(void *handle, uint8_t type, const void *vdata, uint16_t
/* Change newline to null byte, just like non-SPTPS requests */
/* Change newline to null byte, just like non-SPTPS requests */
- if(data[length - 1] == '\n')
+ if(data[length - 1] == '\n')
{
((char *)data)[length - 1] = 0;
((char *)data)[length - 1] = 0;
+ }
/* Otherwise we are waiting for a request */
/* Otherwise we are waiting for a request */
@@
-138,7
+160,7
@@
bool receive_meta_sptps(void *handle, uint8_t type, const void *vdata, uint16_t
}
bool receive_meta(connection_t *c) {
}
bool receive_meta(connection_t *c) {
-
in
t inlen;
+
ssize_
t inlen;
char inbuf[MAXBUFSIZE];
char *bufp = inbuf, *endp;
char inbuf[MAXBUFSIZE];
char *bufp = inbuf, *endp;
@@
-153,22
+175,23
@@
bool receive_meta(connection_t *c) {
buffer_compact(&c->inbuf, MAXBUFSIZE);
buffer_compact(&c->inbuf, MAXBUFSIZE);
- if(sizeof
inbuf
<= c->inbuf.len) {
+ if(sizeof
(inbuf)
<= c->inbuf.len) {
logger(DEBUG_ALWAYS, LOG_ERR, "Input buffer full for %s (%s)", c->name, c->hostname);
return false;
}
logger(DEBUG_ALWAYS, LOG_ERR, "Input buffer full for %s (%s)", c->name, c->hostname);
return false;
}
- inlen = recv(c->socket, inbuf, sizeof
inbuf
- c->inbuf.len, 0);
+ inlen = recv(c->socket, inbuf, sizeof
(inbuf)
- c->inbuf.len, 0);
if(inlen <= 0) {
if(!inlen || !sockerrno) {
logger(DEBUG_CONNECTIONS, LOG_NOTICE, "Connection closed by %s (%s)",
if(inlen <= 0) {
if(!inlen || !sockerrno) {
logger(DEBUG_CONNECTIONS, LOG_NOTICE, "Connection closed by %s (%s)",
-
c->name, c->hostname);
- } else if(sockwouldblock(sockerrno))
+ c->name, c->hostname);
+ } else if(sockwouldblock(sockerrno))
{
return true;
return true;
- else
+
}
else
logger(DEBUG_ALWAYS, LOG_ERR, "Metadata socket read error for %s (%s): %s",
logger(DEBUG_ALWAYS, LOG_ERR, "Metadata socket read error for %s (%s): %s",
- c->name, c->hostname, sockstrerror(sockerrno));
+ c->name, c->hostname, sockstrerror(sockerrno));
+
return false;
}
return false;
}
@@
-176,15
+199,19
@@
bool receive_meta(connection_t *c) {
/* Are we receiving a SPTPS packet? */
if(c->sptpslen) {
/* Are we receiving a SPTPS packet? */
if(c->sptpslen) {
-
in
t len = MIN(inlen, c->sptpslen - c->inbuf.len);
+
ssize_
t len = MIN(inlen, c->sptpslen - c->inbuf.len);
buffer_add(&c->inbuf, bufp, len);
char *sptpspacket = buffer_read(&c->inbuf, c->sptpslen);
buffer_add(&c->inbuf, bufp, len);
char *sptpspacket = buffer_read(&c->inbuf, c->sptpslen);
- if(!sptpspacket)
+
+ if(!sptpspacket) {
return true;
return true;
+ }
- if(!receive_tcppacket_sptps(c, sptpspacket, c->sptpslen))
+ if(!receive_tcppacket_sptps(c, sptpspacket, c->sptpslen))
{
return false;
return false;
+ }
+
c->sptpslen = 0;
bufp += len;
c->sptpslen = 0;
bufp += len;
@@
-193,20
+220,25
@@
bool receive_meta(connection_t *c) {
}
if(c->protocol_minor >= 2) {
}
if(c->protocol_minor >= 2) {
- int len = sptps_receive_data(&c->sptps, bufp, inlen);
- if(!len)
+ size_t len = sptps_receive_data(&c->sptps, bufp, inlen);
+
+ if(!len) {
return false;
return false;
+ }
+
bufp += len;
bufp += len;
- inlen -= len;
+ inlen -=
(ssize_t)
len;
continue;
}
if(!c->status.decryptin) {
endp = memchr(bufp, '\n', inlen);
continue;
}
if(!c->status.decryptin) {
endp = memchr(bufp, '\n', inlen);
- if(endp)
+
+ if(endp) {
endp++;
endp++;
- else
+ } else {
endp = bufp + inlen;
endp = bufp + inlen;
+ }
buffer_add(&c->inbuf, bufp, endp - bufp);
buffer_add(&c->inbuf, bufp, endp - bufp);
@@
-216,11
+248,19
@@
bool receive_meta(connection_t *c) {
#ifdef DISABLE_LEGACY
return false;
#else
#ifdef DISABLE_LEGACY
return false;
#else
+
+ if((size_t)inlen > c->inbudget) {
+ logger(DEBUG_META, LOG_ERR, "Byte limit exceeded for decryption from %s (%s)", c->name, c->hostname);
+ return false;
+ } else {
+ c->inbudget -= inlen;
+ }
+
size_t outlen = inlen;
size_t outlen = inlen;
- if(!cipher_decrypt(
c->incipher, bufp, inlen, buffer_prepare(&c->inbuf, inlen), &outlen, false) ||
inlen != outlen) {
+ if(!cipher_decrypt(
&c->incipher, bufp, inlen, buffer_prepare(&c->inbuf, inlen), &outlen, false) || (size_t)
inlen != outlen) {
logger(DEBUG_ALWAYS, LOG_ERR, "Error while decrypting metadata from %s (%s)",
logger(DEBUG_ALWAYS, LOG_ERR, "Error while decrypting metadata from %s (%s)",
-
c->name, c->hostname);
+ c->name, c->hostname);
return false;
}
return false;
}
@@
-233,8
+273,10
@@
bool receive_meta(connection_t *c) {
if(c->tcplen) {
char *tcpbuffer = buffer_read(&c->inbuf, c->tcplen);
if(c->tcplen) {
char *tcpbuffer = buffer_read(&c->inbuf, c->tcplen);
- if(!tcpbuffer)
+
+ if(!tcpbuffer) {
break;
break;
+ }
if(!c->node) {
if(c->outgoing && proxytype == PROXY_SOCKS4 && c->allow_request == ID) {
if(!c->node) {
if(c->outgoing && proxytype == PROXY_SOCKS4 && c->allow_request == ID) {
@@
-249,14
+291,17
@@
bool receive_meta(connection_t *c) {
logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
return false;
}
logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
return false;
}
+
if(tcpbuffer[1] == (char)0xff) {
logger(DEBUG_CONNECTIONS, LOG_ERR, "Proxy request rejected: unsuitable authentication method");
return false;
}
if(tcpbuffer[1] == (char)0xff) {
logger(DEBUG_CONNECTIONS, LOG_ERR, "Proxy request rejected: unsuitable authentication method");
return false;
}
+
if(tcpbuffer[2] != 5) {
logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
return false;
}
if(tcpbuffer[2] != 5) {
logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
return false;
}
+
if(tcpbuffer[3] == 0) {
logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request granted");
} else {
if(tcpbuffer[3] == 0) {
logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request granted");
} else {
@@
-282,10
+327,14
@@
bool receive_meta(connection_t *c) {
/* Otherwise we are waiting for a request */
char *request = buffer_readline(&c->inbuf);
/* Otherwise we are waiting for a request */
char *request = buffer_readline(&c->inbuf);
+
if(request) {
bool result = receive_request(c, request);
if(request) {
bool result = receive_request(c, request);
- if(!result)
+
+ if(!result) {
return false;
return false;
+ }
+
continue;
} else {
break;
continue;
} else {
break;