X-Git-Url: https://tinc-vpn.org/git/browse?a=blobdiff_plain;f=src%2Fconnection.h;h=600c9542b7769460c10ed4bcb55d4e71a132f18c;hb=2f2bda4d1953617b945f1222e008cb53edee162a;hp=f46d35b808128d1a583707670568cd6fba5418ca;hpb=fcf869cd4250a240ea8d443f70fa373e4fbacf07;p=tinc diff --git a/src/connection.h b/src/connection.h index f46d35b8..600c9542 100644 --- a/src/connection.h +++ b/src/connection.h @@ -1,7 +1,10 @@ +#ifndef TINC_CONNECTION_H +#define TINC_CONNECTION_H + /* connection.h -- header for connection.c - Copyright (C) 2000,2001 Guus Sliepen , - 2000,2001 Ivo Timmermans + Copyright (C) 2000-2013 Guus Sliepen , + 2000-2005 Ivo Timmermans This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by @@ -13,109 +16,125 @@ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. - You should have received a copy of the GNU General Public License - along with this program; if not, write to the Free Software - Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. - - $Id: connection.h,v 1.1.2.9 2001/05/25 11:54:28 guus Exp $ + You should have received a copy of the GNU General Public License along + with this program; if not, write to the Free Software Foundation, Inc., + 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. */ -#ifndef __TINC_CONNECTION_H__ -#define __TINC_CONNECTION_H__ +#include "buffer.h" +#include "cipher.h" +#include "digest.h" +#include "rsa.h" +#include "list.h" +#include "sptps.h" +#include "logger.h" + +#define OPTION_INDIRECT 0x0001 +#define OPTION_TCPONLY 0x0002 +#define OPTION_PMTU_DISCOVERY 0x0004 +#define OPTION_CLAMP_MSS 0x0008 +#define OPTION_VERSION(x) ((x) >> 24) /* Top 8 bits are for protocol minor version */ + +typedef union connection_status_t { + struct { + bool pinged: 1; /* sent ping */ + bool unused_active: 1; + bool connecting: 1; /* 1 if we are waiting for a non-blocking connect() to finish */ + bool unused_termreq: 1; /* the termination of this connection was requested */ + bool remove_unused: 1; /* Set to 1 if you want this connection removed */ + bool timeout_unused: 1; /* 1 if gotten timeout */ + bool encryptout: 1; /* 1 if we can encrypt outgoing traffic */ + bool decryptin: 1; /* 1 if we have to decrypt incoming traffic */ + bool mst: 1; /* 1 if this connection is part of a minimum spanning tree */ + bool control: 1; /* 1 if this is a control connection */ + bool pcap: 1; /* 1 if this is a control connection requesting packet capture */ + bool log: 1; /* 1 if this is a control connection requesting log dump */ + bool log_color: 1; /* 1 if this connection supports ANSI escape codes */ + bool invitation: 1; /* 1 if this is an invitation */ + bool invitation_used: 1; /* 1 if the invitation has been consumed */ + bool tarpit: 1; /* 1 if the connection should be added to the tarpit */ + }; + uint32_t value; +} connection_status_t; + +#include "ecdsa.h" +#include "edge.h" +#include "net.h" +#include "node.h" + +#ifndef DISABLE_LEGACY +typedef struct legacy_crypto_t { + cipher_t cipher; + digest_t digest; + uint64_t budget; +} legacy_crypto_t; + +bool init_crypto_by_nid(legacy_crypto_t *c, nid_t cipher, nid_t digest) ATTR_WARN_UNUSED; +bool init_crypto_by_name(legacy_crypto_t *c, const char *cipher, const char *digest) ATTR_WARN_UNUSED; +bool decrease_budget(legacy_crypto_t *c, size_t bytes) ATTR_WARN_UNUSED; + +typedef struct legacy_ctx_t { + rsa_t *rsa; /* his public RSA key or my private RSA key */ + legacy_crypto_t in; /* cipher/digest he will use to send data to us */ + legacy_crypto_t out; /* cipher/digest we will use to send data to him */ +} legacy_ctx_t; + +legacy_ctx_t *new_legacy_ctx(rsa_t *rsa); +void free_legacy_ctx(legacy_ctx_t *ctx); +#endif + +typedef struct connection_t { + char *name; /* name he claims to have */ + char *hostname; /* the hostname of its real ip */ -#include -#include + union sockaddr_t address; /* his real (internet) ip */ + int protocol_major; /* used protocol */ + int protocol_minor; /* used protocol */ -#include "config.h" + int socket; /* socket used for this connection */ + uint32_t options; /* options for this connection */ + connection_status_t status; /* status info */ + int estimated_weight; /* estimation for the weight of the edge for this connection */ + struct timeval start; /* time this connection was started, used for above estimation */ + struct outgoing_t *outgoing; /* used to keep track of outgoing connections */ -#ifdef HAVE_OPENSSL_EVP_H -# include -#else -# include -#endif + struct node_t *node; /* node associated with the other end */ + struct edge_t *edge; /* edge associated with this connection */ -#ifdef HAVE_OPENSSL_RSA_H -# include -#else -# include +#ifndef DISABLE_LEGACY + legacy_ctx_t *legacy; #endif -#include "net.h" -#include "conf.h" - -typedef struct status_bits_t { - int pinged:1; /* sent ping */ - int meta:1; /* meta connection exists */ - int active:1; /* 1 if active.. */ - int outgoing:1; /* I myself asked for this conn */ - int termreq:1; /* the termination of this connection was requested */ - int remove:1; /* Set to 1 if you want this connection removed */ - int timeout:1; /* 1 if gotten timeout */ - int validkey:1; /* 1 if we currently have a valid key for him */ - int waitingforkey:1; /* 1 if we already sent out a request */ - int dataopen:1; /* 1 if we have a valid UDP connection open */ - int encryptout:1; /* 1 if we can encrypt outgoing traffic */ - int decryptin:1; /* 1 if we have to decrypt incoming traffic */ - int unused:18; -} status_bits_t; - -#define OPTION_INDIRECT 0x0001 -#define OPTION_TCPONLY 0x0002 + ecdsa_t *ecdsa; /* his public ECDSA key */ + sptps_t sptps; -typedef struct connection_t { - char *name; /* name of this connection */ - ipv4_t address; /* his real (internet) ip */ - char *hostname; /* the hostname of its real ip */ - int protocol_version; /* used protocol */ - short unsigned int port; /* port number for UDP traffic */ - long int options; /* options turned on for this connection */ - - int socket; /* our udp vpn socket */ - int meta_socket; /* our tcp meta socket */ - status_bits_t status; /* status info */ - - RSA *rsa_key; /* the public/private key */ - EVP_CIPHER_CTX *cipher_inctx; /* Context of encrypted meta data that will come from him to us */ - EVP_CIPHER_CTX *cipher_outctx; /* Context of encrypted meta data that will be sent from us to him */ - char *cipher_inkey; /* His symmetric meta key */ - char *cipher_outkey; /* Our symmetric meta key */ - EVP_CIPHER *cipher_pkttype; /* Cipher type for encrypted vpn packets */ - char *cipher_pktkey; /* Cipher key and iv */ - int cipher_pktkeylength; /* Cipher key and iv length*/ - - char *buffer; /* metadata input buffer */ - int buflen; /* bytes read into buffer */ - int tcplen; /* length of incoming TCPpacket */ - int allow_request; /* defined if there's only one request possible */ - - time_t last_ping_time; /* last time we saw some activity from the other end */ - - list_t *queue; /* Queue for packets awaiting to be encrypted */ - - char *mychallenge; /* challenge we received from him */ - char *hischallenge; /* challenge we sent to him */ - - struct connection_t *nexthop; /* nearest meta-hop in this direction */ - - avl_tree_t *subnet_tree; /* Pointer to a tree of subnets belonging to this connection */ - - struct config_t *config; /* Pointer to configuration tree belonging to this host */ + int outmaclength; + debug_t log_level; /* used for REQ_LOG */ + + uint8_t *hischallenge; /* The challenge we sent to him */ + uint8_t *mychallenge; /* The challenge we received */ + + struct buffer_t inbuf; + struct buffer_t outbuf; + io_t io; /* input/output event on this metadata connection */ + uint32_t tcplen; /* length of incoming TCPpacket */ + uint32_t sptpslen; /* length of incoming SPTPS packet */ + int allow_request; /* defined if there's only one request possible */ + + time_t last_ping_time; /* last time we saw some activity from the other end or pinged them */ + + splay_tree_t *config_tree; /* Pointer to configuration tree belonging to him */ } connection_t; -extern avl_tree_t *connection_tree; -extern connection_t *myself; +extern list_t connection_list; +extern connection_t *everyone; extern void init_connections(void); -extern connection_t *new_connection(void); -extern void free_connection(connection_t *); -extern void id_add(connection_t *); -extern void connection_add(connection_t *); -extern void connection_del(connection_t *); -extern connection_t *lookup_id(char *); -extern connection_t *lookup_connection(ipv4_t, short unsigned int); -extern void dump_connection_list(void); -extern int read_host_config(connection_t *); -extern void destroy_connection_tree(void); -extern void prune_connection_tree(void); - -#endif /* __TINC_CONNECTION_H__ */ +extern void exit_connections(void); +extern void free_connection(connection_t *c); +extern connection_t *new_connection(void) ATTR_MALLOC ATTR_DEALLOCATOR(free_connection); +extern void connection_add(connection_t *c); +extern void connection_del(connection_t *c); +extern bool dump_connections(struct connection_t *c); + +#endif