/*
meta.c -- handle the meta communication
- Copyright (C) 2000-2009 Guus Sliepen <guus@tinc-vpn.org>,
+ Copyright (C) 2000-2013 Guus Sliepen <guus@tinc-vpn.org>,
2000-2005 Ivo Timmermans
2006 Scott Lamb <slamb@slamb.org>
#include "system.h"
-#include "splay_tree.h"
#include "cipher.h"
#include "connection.h"
#include "logger.h"
#include "utils.h"
#include "xalloc.h"
+bool send_meta_sptps(void *handle, uint8_t type, const char *buffer, size_t length) {
+ connection_t *c = handle;
+
+ if(!c) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "send_meta_sptps() called with NULL pointer!");
+ abort();
+ }
+
+ buffer_add(&c->outbuf, buffer, length);
+ io_set(&c->io, IO_READ | IO_WRITE);
+
+ return true;
+}
+
bool send_meta(connection_t *c, const char *buffer, int length) {
if(!c) {
- logger(LOG_ERR, "send_meta() called with NULL pointer!");
+ logger(DEBUG_ALWAYS, LOG_ERR, "send_meta() called with NULL pointer!");
abort();
}
- ifdebug(META) logger(LOG_DEBUG, "Sending %d bytes of metadata to %s (%s)", length,
+ logger(DEBUG_META, LOG_DEBUG, "Sending %d bytes of metadata to %s (%s)", length,
c->name, c->hostname);
+ if(c->protocol_minor >= 2)
+ return sptps_send_record(&c->sptps, 0, buffer, length);
+
/* Add our data to buffer */
if(c->status.encryptout) {
- char outbuf[length];
size_t outlen = length;
- if(!cipher_encrypt(&c->outcipher, buffer, length, outbuf, &outlen, false) || outlen != length) {
- logger(LOG_ERR, "Error while encrypting metadata to %s (%s)",
+ if(!cipher_encrypt(c->outcipher, buffer, length, buffer_prepare(&c->outbuf, length), &outlen, false) || outlen != length) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Error while encrypting metadata to %s (%s)",
c->name, c->hostname);
return false;
}
-
- ifdebug(META) logger(LOG_DEBUG, "Encrypted write %p %p %p %d", c, c->buffer, outbuf, length);
- bufferevent_write(c->buffer, (void *)outbuf, length);
- ifdebug(META) logger(LOG_DEBUG, "Done.");
} else {
- ifdebug(META) logger(LOG_DEBUG, "Unencrypted write %p %p %p %d", c, c->buffer, buffer, length);
- bufferevent_write(c->buffer, (void *)buffer, length);
- ifdebug(META) logger(LOG_DEBUG, "Done.");
+ buffer_add(&c->outbuf, buffer, length);
}
+ io_set(&c->io, IO_READ | IO_WRITE);
+
return true;
}
void broadcast_meta(connection_t *from, const char *buffer, int length) {
- splay_node_t *node;
- connection_t *c;
+ for list_each(connection_t, c, connection_list)
+ if(c != from && c->edge)
+ send_meta(c, buffer, length);
+}
- for(node = connection_tree->head; node; node = node->next) {
- c = node->data;
+bool receive_meta_sptps(void *handle, uint8_t type, const char *data, uint16_t length) {
+ connection_t *c = handle;
- if(c != from && c->status.active)
- send_meta(c, buffer, length);
+ if(!c) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "receive_meta_sptps() called with NULL pointer!");
+ abort();
+ }
+
+ if(type == SPTPS_HANDSHAKE) {
+ if(c->allow_request == ACK)
+ return send_ack(c);
+ else
+ return true;
+ }
+
+ if(!data)
+ return true;
+
+ /* Are we receiving a TCPpacket? */
+
+ if(c->tcplen) {
+ if(length != c->tcplen)
+ return false;
+ receive_tcppacket(c, data, length);
+ c->tcplen = 0;
+ return true;
}
+
+ /* Change newline to null byte, just like non-SPTPS requests */
+
+ if(data[length - 1] == '\n')
+ ((char *)data)[length - 1] = 0;
+
+ /* Otherwise we are waiting for a request */
+
+ return receive_request(c, data);
}
bool receive_meta(connection_t *c) {
- size_t inlen;
+ int inlen;
char inbuf[MAXBUFSIZE];
char *bufp = inbuf, *endp;
- If not, keep stuff in buffer and exit.
*/
- inlen = recv(c->socket, inbuf, sizeof inbuf, 0);
+ buffer_compact(&c->inbuf, MAXBUFSIZE);
+
+ if(sizeof inbuf <= c->inbuf.len) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Input buffer full for %s (%s)", c->name, c->hostname);
+ return false;
+ }
+
+ inlen = recv(c->socket, inbuf, sizeof inbuf - c->inbuf.len, 0);
if(inlen <= 0) {
- if(!inlen || !errno) {
- ifdebug(CONNECTIONS) logger(LOG_NOTICE, "Connection closed by %s (%s)",
+ if(!inlen || !sockerrno) {
+ logger(DEBUG_CONNECTIONS, LOG_NOTICE, "Connection closed by %s (%s)",
c->name, c->hostname);
} else if(sockwouldblock(sockerrno))
return true;
else
- logger(LOG_ERR, "Metadata socket read error for %s (%s): %s",
+ logger(DEBUG_ALWAYS, LOG_ERR, "Metadata socket read error for %s (%s): %s",
c->name, c->hostname, sockstrerror(sockerrno));
return false;
}
do {
+ if(c->protocol_minor >= 2)
+ return sptps_receive_data(&c->sptps, bufp, inlen);
+
if(!c->status.decryptin) {
endp = memchr(bufp, '\n', inlen);
if(endp)
else
endp = bufp + inlen;
- evbuffer_add(c->buffer->input, bufp, endp - bufp);
+ buffer_add(&c->inbuf, bufp, endp - bufp);
inlen -= endp - bufp;
bufp = endp;
} else {
size_t outlen = inlen;
- ifdebug(META) logger(LOG_DEBUG, "Received encrypted %zu bytes", inlen);
- evbuffer_expand(c->buffer->input, c->buffer->input->off + inlen);
- if(!cipher_decrypt(&c->incipher, bufp, inlen, c->buffer->input->buffer + c->buffer->input->off, &outlen, false) || inlen != outlen) {
- logger(LOG_ERR, "Error while decrypting metadata from %s (%s)",
+ if(!cipher_decrypt(c->incipher, bufp, inlen, buffer_prepare(&c->inbuf, inlen), &outlen, false) || inlen != outlen) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Error while decrypting metadata from %s (%s)",
c->name, c->hostname);
return false;
}
- c->buffer->input->off += inlen;
inlen = 0;
}
- while(c->buffer->input->off) {
+ while(c->inbuf.len) {
/* Are we receiving a TCPpacket? */
if(c->tcplen) {
- if(c->tcplen <= c->buffer->input->off) {
- receive_tcppacket(c, (char *)c->buffer->input->buffer, c->tcplen);
- evbuffer_drain(c->buffer->input, c->tcplen);
- c->tcplen = 0;
- continue;
- } else {
+ char *tcpbuffer = buffer_read(&c->inbuf, c->tcplen);
+ if(!tcpbuffer)
break;
+
+ if(!c->node) {
+ if(c->outgoing && proxytype == PROXY_SOCKS4 && c->allow_request == ID) {
+ if(tcpbuffer[0] == 0 && tcpbuffer[1] == 0x5a) {
+ logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request granted");
+ } else {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Proxy request rejected");
+ return false;
+ }
+ } else if(c->outgoing && proxytype == PROXY_SOCKS5 && c->allow_request == ID) {
+ if(tcpbuffer[0] != 5) {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
+ return false;
+ }
+ if(tcpbuffer[1] == (char)0xff) {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Proxy request rejected: unsuitable authentication method");
+ return false;
+ }
+ if(tcpbuffer[2] != 5) {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
+ return false;
+ }
+ if(tcpbuffer[3] == 0) {
+ logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request granted");
+ } else {
+ logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request rejected");
+ return false;
+ }
+ } else {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "c->tcplen set but c->node is NULL!");
+ abort();
+ }
+ } else {
+ if(c->allow_request == ALL) {
+ receive_tcppacket(c, tcpbuffer, c->tcplen);
+ } else {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Got unauthorized TCP packet from %s (%s)", c->name, c->hostname);
+ return false;
+ }
}
+
+ c->tcplen = 0;
}
/* Otherwise we are waiting for a request */
- char *request = evbuffer_readline(c->buffer->input);
+ char *request = buffer_readline(&c->inbuf);
if(request) {
bool result = receive_request(c, request);
- free(request);
if(!result)
return false;
continue;