+static int cmd_retry(int argc, char *argv[]) {
+ if(!connect_tincd(true))
+ return 1;
+
+ sendline(fd, "%d %d", CONTROL, REQ_RETRY);
+ if(!recvline(fd, line, sizeof line) || sscanf(line, "%d %d %d", &code, &req, &result) != 3 || code != CONTROL || req != REQ_RETRY || result) {
+ fprintf(stderr, "Could not retry outgoing connections.\n");
+ return 1;
+ }
+
+ return 0;
+}
+
+static int cmd_connect(int argc, char *argv[]) {
+ if(argc != 2) {
+ fprintf(stderr, "Invalid number of arguments.\n");
+ return 1;
+ }
+
+ if(!check_id(argv[1])) {
+ fprintf(stderr, "Invalid name for node.\n");
+ return 1;
+ }
+
+ if(!connect_tincd(true))
+ return 1;
+
+ sendline(fd, "%d %d %s", CONTROL, REQ_CONNECT, argv[1]);
+ if(!recvline(fd, line, sizeof line) || sscanf(line, "%d %d %d", &code, &req, &result) != 3 || code != CONTROL || req != REQ_CONNECT || result) {
+ fprintf(stderr, "Could not connect to %s.\n", argv[1]);
+ return 1;
+ }
+
+ return 0;
+}
+
+static int cmd_disconnect(int argc, char *argv[]) {
+ if(argc != 2) {
+ fprintf(stderr, "Invalid number of arguments.\n");
+ return 1;
+ }
+
+ if(!check_id(argv[1])) {
+ fprintf(stderr, "Invalid name for node.\n");
+ return 1;
+ }
+
+ if(!connect_tincd(true))
+ return 1;
+
+ sendline(fd, "%d %d %s", CONTROL, REQ_DISCONNECT, argv[1]);
+ if(!recvline(fd, line, sizeof line) || sscanf(line, "%d %d %d", &code, &req, &result) != 3 || code != CONTROL || req != REQ_DISCONNECT || result) {
+ fprintf(stderr, "Could not disconnect %s.\n", argv[1]);
+ return 1;
+ }
+
+ return 0;
+}
+
+static int cmd_top(int argc, char *argv[]) {
+#ifdef HAVE_CURSES
+ if(!connect_tincd(true))
+ return 1;
+
+ top(fd);
+ return 0;
+#else
+ fprintf(stderr, "This version of tincctl was compiled without support for the curses library.\n");
+ return 1;
+#endif
+}
+
+static int cmd_pcap(int argc, char *argv[]) {
+ if(!connect_tincd(true))
+ return 1;
+
+ pcap(fd, stdout, argc > 1 ? atoi(argv[1]) : 0);
+ return 0;
+}
+
+static int cmd_log(int argc, char *argv[]) {
+ if(!connect_tincd(true))
+ return 1;
+
+ logcontrol(fd, stdout, argc > 1 ? atoi(argv[1]) : -1);
+ return 0;
+}
+
+static int cmd_pid(int argc, char *argv[]) {
+ if(!connect_tincd(true) && !pid)
+ return 1;
+
+ printf("%d\n", pid);
+ return 0;
+}
+
+static int rstrip(char *value) {
+ int len = strlen(value);
+ while(len && strchr("\t\r\n ", value[len - 1]))
+ value[--len] = 0;
+ return len;
+}
+
+static char *get_my_name() {
+ FILE *f = fopen(tinc_conf, "r");
+ if(!f) {
+ fprintf(stderr, "Could not open %s: %s\n", tinc_conf, strerror(errno));
+ return NULL;
+ }
+
+ char buf[4096];
+ char *value;
+ while(fgets(buf, sizeof buf, f)) {
+ int len = strcspn(buf, "\t =");
+ value = buf + len;
+ value += strspn(value, "\t ");
+ if(*value == '=') {
+ value++;
+ value += strspn(value, "\t ");
+ }
+ if(!rstrip(value))
+ continue;
+ buf[len] = 0;
+ if(strcasecmp(buf, "Name"))
+ continue;
+ if(*value) {
+ fclose(f);
+ return strdup(value);
+ }
+ }
+
+ fclose(f);
+ fprintf(stderr, "Could not find Name in %s.\n", tinc_conf);
+ return NULL;
+}
+
+#define VAR_SERVER 1 /* Should be in tinc.conf */
+#define VAR_HOST 2 /* Can be in host config file */
+#define VAR_MULTIPLE 4 /* Multiple statements allowed */
+#define VAR_OBSOLETE 8 /* Should not be used anymore */
+
+static struct {
+ const char *name;
+ int type;
+} const variables[] = {
+ /* Server configuration */
+ {"AddressFamily", VAR_SERVER},
+ {"AutoConnect", VAR_SERVER},
+ {"BindToAddress", VAR_SERVER | VAR_MULTIPLE},
+ {"BindToInterface", VAR_SERVER},
+ {"Broadcast", VAR_SERVER},
+ {"ConnectTo", VAR_SERVER | VAR_MULTIPLE},
+ {"DecrementTTL", VAR_SERVER},
+ {"Device", VAR_SERVER},
+ {"DeviceType", VAR_SERVER},
+ {"DirectOnly", VAR_SERVER},
+ {"ECDSAPrivateKeyFile", VAR_SERVER},
+ {"ExperimentalProtocol", VAR_SERVER},
+ {"Forwarding", VAR_SERVER},
+ {"GraphDumpFile", VAR_SERVER | VAR_OBSOLETE},
+ {"Hostnames", VAR_SERVER},
+ {"IffOneQueue", VAR_SERVER},
+ {"Interface", VAR_SERVER},
+ {"KeyExpire", VAR_SERVER},
+ {"LocalDiscovery", VAR_SERVER},
+ {"MACExpire", VAR_SERVER},
+ {"MaxOutputBufferSize", VAR_SERVER},
+ {"MaxTimeout", VAR_SERVER},
+ {"Mode", VAR_SERVER},
+ {"Name", VAR_SERVER},
+ {"PingInterval", VAR_SERVER},
+ {"PingTimeout", VAR_SERVER},
+ {"PriorityInheritance", VAR_SERVER},
+ {"PrivateKey", VAR_SERVER | VAR_OBSOLETE},
+ {"PrivateKeyFile", VAR_SERVER},
+ {"ProcessPriority", VAR_SERVER},
+ {"Proxy", VAR_SERVER},
+ {"ReplayWindow", VAR_SERVER},
+ {"ScriptsExtension", VAR_SERVER},
+ {"ScriptsInterpreter", VAR_SERVER},
+ {"StrictSubnets", VAR_SERVER},
+ {"TunnelServer", VAR_SERVER},
+ {"UDPRcvBuf", VAR_SERVER},
+ {"UDPSndBuf", VAR_SERVER},
+ {"VDEGroup", VAR_SERVER},
+ {"VDEPort", VAR_SERVER},
+ /* Host configuration */
+ {"Address", VAR_HOST | VAR_MULTIPLE},
+ {"Cipher", VAR_SERVER | VAR_HOST},
+ {"ClampMSS", VAR_SERVER | VAR_HOST},
+ {"Compression", VAR_SERVER | VAR_HOST},
+ {"Digest", VAR_SERVER | VAR_HOST},
+ {"ECDSAPublicKey", VAR_HOST},
+ {"ECDSAPublicKeyFile", VAR_SERVER | VAR_HOST},
+ {"IndirectData", VAR_SERVER | VAR_HOST},
+ {"MACLength", VAR_SERVER | VAR_HOST},
+ {"PMTU", VAR_SERVER | VAR_HOST},
+ {"PMTUDiscovery", VAR_SERVER | VAR_HOST},
+ {"Port", VAR_HOST},
+ {"PublicKey", VAR_HOST | VAR_OBSOLETE},
+ {"PublicKeyFile", VAR_SERVER | VAR_HOST | VAR_OBSOLETE},
+ {"Subnet", VAR_HOST | VAR_MULTIPLE},
+ {"TCPOnly", VAR_SERVER | VAR_HOST},
+ {"Weight", VAR_HOST},
+ {NULL, 0}
+};
+
+static int cmd_config(int argc, char *argv[]) {
+ if(argc < 2) {
+ fprintf(stderr, "Invalid number of arguments.\n");
+ return 1;
+ }
+
+ int action = -2;
+ if(!strcasecmp(argv[1], "get")) {
+ argv++, argc--;
+ } else if(!strcasecmp(argv[1], "add")) {
+ argv++, argc--, action = 1;
+ } else if(!strcasecmp(argv[1], "del")) {
+ argv++, argc--, action = -1;
+ } else if(!strcasecmp(argv[1], "replace") || !strcasecmp(argv[1], "set") || !strcasecmp(argv[1], "change")) {
+ argv++, argc--, action = 0;
+ }
+
+ if(argc < 2) {
+ fprintf(stderr, "Invalid number of arguments.\n");
+ return 1;
+ }
+
+ // Concatenate the rest of the command line
+ strncpy(line, argv[1], sizeof line - 1);
+ for(int i = 2; i < argc; i++) {
+ strncat(line, " ", sizeof line - 1 - strlen(line));
+ strncat(line, argv[i], sizeof line - 1 - strlen(line));
+ }
+
+ // Liberal parsing into node name, variable name and value.
+ char *node = NULL;
+ char *variable;
+ char *value;
+ int len;
+
+ len = strcspn(line, "\t =");
+ value = line + len;
+ value += strspn(value, "\t ");
+ if(*value == '=') {
+ value++;
+ value += strspn(value, "\t ");
+ }
+ line[len] = '\0';
+ variable = strchr(line, '.');
+ if(variable) {
+ node = line;
+ *variable++ = 0;
+ } else {
+ variable = line;
+ }
+
+ if(!*variable) {
+ fprintf(stderr, "No variable given.\n");
+ return 1;
+ }
+
+ if(action >= 0 && !*value) {
+ fprintf(stderr, "No value for variable given.\n");
+ return 1;
+ }
+
+ if(action < -1 && *value)
+ action = 0;
+
+ /* Some simple checks. */
+ bool found = false;
+
+ for(int i = 0; variables[i].name; i++) {
+ if(strcasecmp(variables[i].name, variable))
+ continue;
+
+ found = true;
+ variable = (char *)variables[i].name;
+
+ /* Discourage use of obsolete variables. */
+
+ if(variables[i].type & VAR_OBSOLETE && action >= 0) {
+ if(force) {
+ fprintf(stderr, "Warning: %s is an obsolete variable!\n", variable);
+ } else {
+ fprintf(stderr, "%s is an obsolete variable! Use --force to use it anyway.\n", variable);
+ return 1;
+ }
+ }
+
+ /* Don't put server variables in host config files */
+
+ if(node && !(variables[i].type & VAR_HOST) && action >= 0) {
+ if(force) {
+ fprintf(stderr, "Warning: %s is not a host configuration variable!\n", variable);
+ } else {
+ fprintf(stderr, "%s is not a host configuration variable! Use --force to use it anyway.\n", variable);
+ return 1;
+ }
+ }
+
+ /* Should this go into our own host config file? */
+
+ if(!node && !(variables[i].type & VAR_SERVER)) {
+ node = get_my_name();
+ if(!node)
+ return 1;
+ }
+
+ break;
+ }
+
+ if(node && !check_id(node)) {
+ fprintf(stderr, "Invalid name for node.\n");
+ return 1;
+ }
+
+ if(!found) {
+ if(force || action < 0) {
+ fprintf(stderr, "Warning: %s is not a known configuration variable!\n", variable);
+ } else {
+ fprintf(stderr, "%s: is not a known configuration variable! Use --force to use it anyway.\n", variable);
+ return 1;
+ }
+ }
+
+ // Open the right configuration file.
+ char *filename;
+ if(node)
+ xasprintf(&filename, "%s" SLASH "%s", hosts_dir, node);
+ else
+ filename = tinc_conf;
+
+ FILE *f = fopen(filename, "r");
+ if(!f) {
+ if(action < 0 || errno != ENOENT) {
+ fprintf(stderr, "Could not open configuration file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+
+ // If it doesn't exist, create it.
+ f = fopen(filename, "a+");
+ if(!f) {
+ fprintf(stderr, "Could not create configuration file %s: %s\n", filename, strerror(errno));
+ return 1;
+ } else {
+ fprintf(stderr, "Created configuration file %s.\n", filename);
+ }
+ }
+
+ char *tmpfile = NULL;
+ FILE *tf = NULL;
+
+ if(action >= -1) {
+ xasprintf(&tmpfile, "%s.config.tmp", filename);
+ tf = fopen(tmpfile, "w");
+ if(!tf) {
+ fprintf(stderr, "Could not open temporary file %s: %s\n", tmpfile, strerror(errno));
+ fclose(f);
+ return 1;
+ }
+ }
+
+ // Copy the file, making modifications on the fly, unless we are just getting a value.
+ char buf1[4096];
+ char buf2[4096];
+ bool set = false;
+ bool removed = false;
+ found = false;
+
+ while(fgets(buf1, sizeof buf1, f)) {
+ buf1[sizeof buf1 - 1] = 0;
+ strncpy(buf2, buf1, sizeof buf2);
+
+ // Parse line in a simple way
+ char *bvalue;
+ int len;
+
+ len = strcspn(buf2, "\t =");
+ bvalue = buf2 + len;
+ bvalue += strspn(bvalue, "\t ");
+ if(*bvalue == '=') {
+ bvalue++;
+ bvalue += strspn(bvalue, "\t ");
+ }
+ rstrip(bvalue);
+ buf2[len] = '\0';
+
+ // Did it match?
+ if(!strcasecmp(buf2, variable)) {
+ // Get
+ if(action < -1) {
+ found = true;
+ printf("%s\n", bvalue);
+ // Del
+ } else if(action == -1) {
+ if(!*value || !strcasecmp(bvalue, value)) {
+ removed = true;
+ continue;
+ }
+ // Set
+ } else if(action == 0) {
+ // Already set? Delete the rest...
+ if(set)
+ continue;
+ // Otherwise, replace.
+ if(fprintf(tf, "%s = %s\n", variable, value) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+ set = true;
+ continue;
+ }
+ }
+
+ if(action >= -1) {
+ // Copy original line...
+ if(fputs(buf1, tf) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+
+ // Add newline if it is missing...
+ if(*buf1 && buf1[strlen(buf1) - 1] != '\n') {
+ if(fputc('\n', tf) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+ }
+ }
+ }
+
+ // Make sure we read everything...
+ if(ferror(f) || !feof(f)) {
+ fprintf(stderr, "Error while reading from configuration file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+
+ if(fclose(f)) {
+ fprintf(stderr, "Error closing configuration file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+
+ // Add new variable if necessary.
+ if(action > 0 || (action == 0 && !set)) {
+ if(fprintf(tf, "%s = %s\n", variable, value) < 0) {
+ fprintf(stderr, "Error writing to temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+ }
+
+ if(action < -1) {
+ if(!found)
+ fprintf(stderr, "No matching configuration variables found.\n");
+ return 0;
+ }
+
+ // Make sure we wrote everything...
+ if(fclose(tf)) {
+ fprintf(stderr, "Error closing temporary file %s: %s\n", tmpfile, strerror(errno));
+ return 1;
+ }
+
+ // Could we find what we had to remove?
+ if(action < 0 && !removed) {
+ remove(tmpfile);
+ fprintf(stderr, "No configuration variables deleted.\n");
+ return *value;
+ }
+
+ // Replace the configuration file with the new one
+#ifdef HAVE_MINGW
+ if(remove(filename)) {
+ fprintf(stderr, "Error replacing file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+#endif
+ if(rename(tmpfile, filename)) {
+ fprintf(stderr, "Error renaming temporary file %s to configuration file %s: %s\n", tmpfile, filename, strerror(errno));
+ return 1;
+ }
+
+ // Silently try notifying a running tincd of changes.
+ if(connect_tincd(false))
+ sendline(fd, "%d %d", CONTROL, REQ_RELOAD);
+
+ return 0;
+}
+
+bool check_id(const char *name) {
+ if(!name || !*name)
+ return false;
+
+ for(int i = 0; i < strlen(name); i++) {
+ if(!isalnum(name[i]) && name[i] != '_')
+ return false;
+ }
+
+ return true;
+}
+
+static int cmd_init(int argc, char *argv[]) {
+ if(!access(tinc_conf, F_OK)) {
+ fprintf(stderr, "Configuration file %s already exists!\n", tinc_conf);
+ return 1;
+ }
+
+ if(argc < 2) {
+ if(tty) {
+ char buf[1024];
+ fprintf(stdout, "Enter the Name you want your tinc node to have: ");
+ fflush(stdout);
+ if(!fgets(buf, sizeof buf, stdin)) {
+ fprintf(stderr, "Error while reading stdin: %s\n", strerror(errno));
+ return 1;
+ }
+ int len = rstrip(buf);
+ if(!len) {
+ fprintf(stderr, "No name given!\n");
+ return 1;
+ }
+ name = strdup(buf);
+ } else {
+ fprintf(stderr, "No Name given!\n");
+ return 1;
+ }
+ } else {
+ name = strdup(argv[1]);
+ if(!*name) {
+ fprintf(stderr, "No Name given!\n");
+ return 1;
+ }
+ }
+
+ if(!check_id(name)) {
+ fprintf(stderr, "Invalid Name! Only a-z, A-Z, 0-9 and _ are allowed characters.\n");
+ return 1;
+ }
+
+ if(mkdir(confdir, 0755) && errno != EEXIST) {
+ fprintf(stderr, "Could not create directory %s: %s\n", CONFDIR, strerror(errno));
+ return 1;
+ }
+
+ if(mkdir(confbase, 0755) && errno != EEXIST) {
+ fprintf(stderr, "Could not create directory %s: %s\n", confbase, strerror(errno));
+ return 1;
+ }
+
+ if(mkdir(hosts_dir, 0755) && errno != EEXIST) {
+ fprintf(stderr, "Could not create directory %s: %s\n", hosts_dir, strerror(errno));
+ return 1;
+ }
+
+ FILE *f = fopen(tinc_conf, "w");
+ if(!f) {
+ fprintf(stderr, "Could not create file %s: %s\n", tinc_conf, strerror(errno));
+ return 1;
+ }
+
+ fprintf(f, "Name = %s\n", name);
+ fclose(f);
+
+ if(!rsa_keygen(2048, false) || !ecdsa_keygen(false))
+ return 1;
+
+#ifndef HAVE_MINGW
+ char *filename;
+ xasprintf(&filename, "%s" SLASH "tinc-up", confbase);
+ if(access(filename, F_OK)) {
+ FILE *f = fopen(filename, "w");
+ if(!f) {
+ fprintf(stderr, "Could not create file %s: %s\n", filename, strerror(errno));
+ return 1;
+ }
+ fchmod(fileno(f), 0755);
+ fprintf(f, "#!/bin/sh\n\necho 'Unconfigured tinc-up script, please edit!'\n\n#ifconfig $INTERFACE <your vpn IP address> netmask <netmask of whole VPN>\n");
+ fclose(f);
+ }
+#endif