/*
net_socket.c -- Handle various kinds of sockets.
Copyright (C) 1998-2005 Ivo Timmermans,
- 2000-2017 Guus Sliepen <guus@tinc-vpn.org>
+ 2000-2018 Guus Sliepen <guus@tinc-vpn.org>
2006 Scott Lamb <slamb@slamb.org>
2009 Florian Forster <octo@verplant.org>
#include "address_cache.h"
#include "conf.h"
#include "connection.h"
-#include "control_common.h"
+#include "crypto.h"
#include "list.h"
#include "logger.h"
-#include "meta.h"
#include "names.h"
#include "net.h"
#include "netutl.h"
int seconds_till_retry = 5;
int udp_rcvbuf = 1024 * 1024;
int udp_sndbuf = 1024 * 1024;
-int max_connection_burst = 100;
+bool udp_rcvbuf_warnings;
+bool udp_sndbuf_warnings;
+int max_connection_burst = 10;
+int fwmark;
listen_socket_t listen_socket[MAXSOCKETS];
int listen_sockets;
-#ifndef HAVE_MINGW
+#ifndef HAVE_WINDOWS
io_t unix_socket;
#endif
-list_t *outgoing_list = NULL;
+
+static void free_outgoing(outgoing_t *outgoing) {
+ timeout_del(&outgoing->ev);
+ free(outgoing);
+}
+
+list_t outgoing_list = {
+ .head = NULL,
+ .tail = NULL,
+ .count = 0,
+ .delete = (list_action_t)free_outgoing,
+};
/* Setup sockets */
int flags = fcntl(c->socket, F_GETFL);
if(fcntl(c->socket, F_SETFL, flags | O_NONBLOCK) < 0) {
- logger(DEBUG_ALWAYS, LOG_ERR, "fcntl for %s: %s", c->hostname, strerror(errno));
+ logger(DEBUG_ALWAYS, LOG_ERR, "fcntl for %s fd %d: %s", c->hostname, c->socket, strerror(errno));
}
#elif defined(WIN32)
unsigned long arg = 1;
if(ioctlsocket(c->socket, FIONBIO, &arg) != 0) {
- logger(DEBUG_ALWAYS, LOG_ERR, "ioctlsocket for %s: %s", c->hostname, sockstrerror(sockerrno));
+ logger(DEBUG_ALWAYS, LOG_ERR, "ioctlsocket for %s fd %d: %s", c->hostname, c->socket, sockstrerror(sockerrno));
}
#endif
option = IPTOS_LOWDELAY;
setsockopt(c->socket, IPPROTO_IPV6, IPV6_TCLASS, (void *)&option, sizeof(option));
#endif
+
+#if defined(SO_MARK)
+
+ if(fwmark) {
+ setsockopt(c->socket, SOL_SOCKET, SO_MARK, (void *)&fwmark, sizeof(fwmark));
+ }
+
+#endif
}
static bool bind_to_interface(int sd) {
int status;
#endif /* defined(SOL_SOCKET) && defined(SO_BINDTODEVICE) */
- if(!get_config_string(lookup_config(config_tree, "BindToInterface"), &iface)) {
+ if(!get_config_string(lookup_config(&config_tree, "BindToInterface"), &iface)) {
return true;
}
}
#else /* if !defined(SOL_SOCKET) || !defined(SO_BINDTODEVICE) */
+ (void)sd;
logger(DEBUG_ALWAYS, LOG_WARNING, "%s not supported on this platform", "BindToInterface");
#endif
#else
#warning IPV6_V6ONLY not defined
+#endif
+
+#if defined(SO_MARK)
+
+ if(fwmark) {
+ setsockopt(nfd, SOL_SOCKET, SO_MARK, (void *)&fwmark, sizeof(fwmark));
+ }
+
#endif
if(get_config_string
- (lookup_config(config_tree, "BindToInterface"), &iface)) {
+ (lookup_config(&config_tree, "BindToInterface"), &iface)) {
#if defined(SOL_SOCKET) && defined(SO_BINDTODEVICE)
struct ifreq ifr;
memset(&ifr, 0, sizeof(ifr));
strncpy(ifr.ifr_ifrn.ifrn_name, iface, IFNAMSIZ);
+ ifr.ifr_ifrn.ifrn_name[IFNAMSIZ - 1] = 0;
if(setsockopt(nfd, SOL_SOCKET, SO_BINDTODEVICE, (void *)&ifr, sizeof(ifr))) {
closesocket(nfd);
return nfd;
}
+static void set_udp_buffer(int nfd, int type, const char *name, int size, bool warnings) {
+ if(!size) {
+ return;
+ }
+
+ if(setsockopt(nfd, SOL_SOCKET, type, (void *)&size, sizeof(size))) {
+ logger(DEBUG_ALWAYS, LOG_WARNING, "Can't set UDP %s to %i: %s", name, size, sockstrerror(sockerrno));
+ return;
+ }
+
+ if(!warnings) {
+ return;
+ }
+
+ // The system may cap the requested buffer size.
+ // Read back the value and check if it is now as requested.
+ int actual = -1;
+ socklen_t optlen = sizeof(actual);
+
+ if(getsockopt(nfd, SOL_SOCKET, type, (void *)&actual, &optlen)) {
+ logger(DEBUG_ALWAYS, LOG_WARNING, "Can't read back UDP %s: %s", name, sockstrerror(sockerrno));
+ } else if(optlen != sizeof(actual)) {
+ logger(DEBUG_ALWAYS, LOG_WARNING, "Can't read back UDP %s: unexpected returned optlen %d", name, (int)optlen);
+ } else if(actual < size) {
+ logger(DEBUG_ALWAYS, LOG_WARNING, "Can't set UDP %s to %i, the system set it to %i instead", name, size, actual);
+ }
+}
+
+
int setup_vpn_in_socket(const sockaddr_t *sa) {
int nfd;
char *addrstr;
setsockopt(nfd, SOL_SOCKET, SO_REUSEADDR, (void *)&option, sizeof(option));
setsockopt(nfd, SOL_SOCKET, SO_BROADCAST, (void *)&option, sizeof(option));
- if(udp_rcvbuf && setsockopt(nfd, SOL_SOCKET, SO_RCVBUF, (void *)&udp_rcvbuf, sizeof(udp_rcvbuf))) {
- logger(DEBUG_ALWAYS, LOG_WARNING, "Can't set UDP SO_RCVBUF to %i: %s", udp_rcvbuf, sockstrerror(sockerrno));
- }
-
- if(udp_sndbuf && setsockopt(nfd, SOL_SOCKET, SO_SNDBUF, (void *)&udp_sndbuf, sizeof(udp_sndbuf))) {
- logger(DEBUG_ALWAYS, LOG_WARNING, "Can't set UDP SO_SNDBUF to %i: %s", udp_sndbuf, sockstrerror(sockerrno));
- }
+ set_udp_buffer(nfd, SO_RCVBUF, "SO_RCVBUF", udp_rcvbuf, udp_rcvbuf_warnings);
+ set_udp_buffer(nfd, SO_SNDBUF, "SO_SNDBUF", udp_sndbuf, udp_sndbuf_warnings);
#if defined(IPV6_V6ONLY)
setsockopt(nfd, IPPROTO_IPV6, IPV6_DONTFRAG, (void *)&option, sizeof(option));
}
+#endif
+
+#if defined(SO_MARK)
+
+ if(fwmark) {
+ setsockopt(nfd, SOL_SOCKET, SO_MARK, (void *)&fwmark, sizeof(fwmark));
+ }
+
#endif
if(!bind_to_interface(nfd)) {
}
timeout_add(&outgoing->ev, retry_outgoing_handler, outgoing, &(struct timeval) {
- outgoing->timeout, rand() % 100000
+ outgoing->timeout, jitter()
});
logger(DEBUG_CONNECTIONS, LOG_NOTICE, "Trying to re-establish outgoing connection in %d seconds", outgoing->timeout);
send_id(c);
}
-static void do_outgoing_pipe(connection_t *c, char *command) {
-#ifndef HAVE_MINGW
+static void do_outgoing_pipe(connection_t *c, const char *command) {
+#ifndef HAVE_WINDOWS
int fd[2];
if(socketpair(AF_UNIX, SOCK_STREAM, 0, fd)) {
exit(result);
#else
+ (void)c;
+ (void)command;
logger(DEBUG_ALWAYS, LOG_ERR, "Proxy type exec not supported on this platform!");
return;
#endif
int result;
begin:
- sa = get_recent_address(outgoing->address_cache);
+ sa = get_recent_address(outgoing->node->address_cache);
if(!sa) {
logger(DEBUG_CONNECTIONS, LOG_ERR, "Could not set up a meta connection to %s", outgoing->node->name);
connection_t *c = new_connection();
c->outgoing = outgoing;
- c->address = *sa;
+ memcpy(&c->address, sa, SALEN(sa->sa));
c->hostname = sockaddr2hostname(&c->address);
logger(DEBUG_CONNECTIONS, LOG_INFO, "Trying to connect to %s (%s)", outgoing->node->name, c->hostname);
}
void setup_outgoing_connection(outgoing_t *outgoing, bool verbose) {
+ (void)verbose;
timeout_del(&outgoing->ev);
node_t *n = outgoing->node;
+ if(!n->address_cache) {
+ n->address_cache = open_address_cache(n);
+ }
+
if(n->connection) {
logger(DEBUG_CONNECTIONS, LOG_INFO, "Already connected to %s", n->name);
}
}
- if(!outgoing->address_cache) {
- outgoing->address_cache = open_address_cache(n);
- }
-
do_outgoing_connection(outgoing);
return;
remove:
- list_delete(outgoing_list, outgoing);
+ list_delete(&outgoing_list, outgoing);
}
/*
new connection
*/
void handle_new_meta_connection(void *data, int flags) {
+ (void)flags;
listen_socket_t *l = data;
connection_t *c;
sockaddr_t sa;
// Check if we get many connections from the same host
static sockaddr_t prev_sa;
- static int tarpit = -1;
-
- if(tarpit >= 0) {
- closesocket(tarpit);
- tarpit = -1;
- }
if(!sockaddrcmp_noport(&sa, &prev_sa)) {
- static int samehost_burst;
- static int samehost_burst_time;
+ static time_t samehost_burst;
+ static time_t samehost_burst_time;
if(now.tv_sec - samehost_burst_time > samehost_burst) {
samehost_burst = 0;
samehost_burst++;
if(samehost_burst > max_connection_burst) {
- tarpit = fd;
+ tarpit(fd);
return;
}
}
// Check if we get many connections from different hosts
- static int connection_burst;
- static int connection_burst_time;
+ static time_t connection_burst;
+ static time_t connection_burst_time;
if(now.tv_sec - connection_burst_time > connection_burst) {
connection_burst = 0;
if(connection_burst >= max_connection_burst) {
connection_burst = max_connection_burst;
- tarpit = fd;
+ tarpit(fd);
return;
}
connection_add(c);
c->allow_request = ID;
- send_id(c);
}
-#ifndef HAVE_MINGW
+#ifndef HAVE_WINDOWS
/*
accept a new UNIX socket connection
*/
void handle_new_unix_connection(void *data, int flags) {
+ (void)flags;
io_t *io = data;
connection_t *c;
sockaddr_t sa;
connection_add(c);
c->allow_request = ID;
-
- send_id(c);
}
#endif
-static void free_outgoing(outgoing_t *outgoing) {
- timeout_del(&outgoing->ev);
-
- if(outgoing->address_cache) {
- close_address_cache(outgoing->address_cache);
- }
-
- free(outgoing);
-}
-
void try_outgoing_connections(void) {
/* If there is no outgoing list yet, create one. Otherwise, mark all outgoings as deleted. */
- if(!outgoing_list) {
- outgoing_list = list_alloc((list_action_t)free_outgoing);
- } else {
- for list_each(outgoing_t, outgoing, outgoing_list) {
- outgoing->timeout = -1;
- }
+ for list_each(outgoing_t, outgoing, &outgoing_list) {
+ outgoing->timeout = -1;
}
/* Make sure there is one outgoing_t in the list for each ConnectTo. */
- for(config_t *cfg = lookup_config(config_tree, "ConnectTo"); cfg; cfg = lookup_config_next(config_tree, cfg)) {
+ for(config_t *cfg = lookup_config(&config_tree, "ConnectTo"); cfg; cfg = lookup_config_next(&config_tree, cfg)) {
char *name;
get_config_string(cfg, &name);
bool found = false;
- for list_each(outgoing_t, outgoing, outgoing_list) {
+ for list_each(outgoing_t, outgoing, &outgoing_list) {
if(!strcmp(outgoing->node->name, name)) {
found = true;
outgoing->timeout = 0;
if(!found) {
outgoing_t *outgoing = xzalloc(sizeof(*outgoing));
node_t *n = lookup_node(name);
+
if(!n) {
n = new_node();
n->name = xstrdup(name);
node_add(n);
}
+
+ free(name);
+
outgoing->node = n;
- list_insert_tail(outgoing_list, outgoing);
+ list_insert_tail(&outgoing_list, outgoing);
setup_outgoing_connection(outgoing, true);
}
}
/* Terminate any connections whose outgoing_t is to be deleted. */
- for list_each(connection_t, c, connection_list) {
+ for list_each(connection_t, c, &connection_list) {
if(c->outgoing && c->outgoing->timeout == -1) {
c->outgoing = NULL;
logger(DEBUG_CONNECTIONS, LOG_INFO, "No more outgoing connection to %s", c->name);
/* Delete outgoing_ts for which there is no ConnectTo. */
- for list_each(outgoing_t, outgoing, outgoing_list)
+ for list_each(outgoing_t, outgoing, &outgoing_list)
if(outgoing->timeout == -1) {
- list_delete_node(outgoing_list, node);
+ list_delete_node(&outgoing_list, node);
}
}