tinc
14 years agoTry to set DF bit on BSDs as well.
Guus Sliepen [Tue, 2 Feb 2010 21:22:27 +0000 (22:22 +0100)]
Try to set DF bit on BSDs as well.

Every operating system seems to have its own, slightly different way to disable
packet fragmentation. Emit a compiler warning when no suitable way is found.
On OpenBSD, it seems impossible to do it for IPv4.

14 years agoImmediately exchange keys when establishing a meta connection.
Guus Sliepen [Tue, 2 Feb 2010 00:02:40 +0000 (01:02 +0100)]
Immediately exchange keys when establishing a meta connection.

This in turn will trigger PMTU discovery, and ensures nodes know each others
reflexive UDP address and port.

14 years agoDetermine peer's reflexive address and port when exchanging keys.
Guus Sliepen [Mon, 1 Feb 2010 23:51:44 +0000 (00:51 +0100)]
Determine peer's reflexive address and port when exchanging keys.

To help peers that are behind NAT connect to each other directly via UDP, they
need to know the exact external address and port that they use. Keys exchanged
between NATted peers necessarily go via a third node, which knows this address
and port, and can append this information to the keys, which is in turned used
by the peers.

Since PMTU discovery will immediately trigger UDP communication from both sides
to each other, this should allow direct communication between peers behind
full, address-restricted and port-restricted cone NAT.

14 years agoBe liberal in accepting KEY_CHANGED/REQ_KEY/ANS_KEY requests.
Guus Sliepen [Sat, 23 Jan 2010 17:48:01 +0000 (18:48 +0100)]
Be liberal in accepting KEY_CHANGED/REQ_KEY/ANS_KEY requests.

When we got a key request for or from a node we don't know, we disconnected the
node that forwarded us that request.  However, especially in TunnelServer mode,
disconnecting does not help. We now ignore such requests, but since there is no
way of telling the original sender that the request was dropped, we now retry
sending REQ_KEY requests when we don't get an ANS_KEY back.

14 years agoRun subnet-up/down scripts for local MAC addresses as well.
Guus Sliepen [Fri, 22 Jan 2010 20:59:40 +0000 (21:59 +0100)]
Run subnet-up/down scripts for local MAC addresses as well.

14 years agoFix subnet-up/down scripts being called with an empty SUBNET.
Guus Sliepen [Fri, 22 Jan 2010 20:47:26 +0000 (21:47 +0100)]
Fix subnet-up/down scripts being called with an empty SUBNET.

Commit 052ff8b2c598358d1c5febaa9f9f5fc5d384cfd3 contained a bug that causes
scripts to be called with an empty, or possibly corrupted SUBNET variable when
a Subnet is added or removed while the owner is still online. In router mode,
this normally does not happen, but in switch mode this is normal.

14 years agoMake MSS clamping configurable, but enabled by default.
Guus Sliepen [Sat, 16 Jan 2010 19:16:33 +0000 (20:16 +0100)]
Make MSS clamping configurable, but enabled by default.

It can either be set globally in tinc.conf, or per-node in host config files.

14 years agoAlso clamp MSS of TCP over IPv6 packets.
Guus Sliepen [Sat, 16 Jan 2010 18:32:33 +0000 (19:32 +0100)]
Also clamp MSS of TCP over IPv6 packets.

14 years agoOptimise handling of select() returning <= 0.
Guus Sliepen [Fri, 15 Jan 2010 22:41:14 +0000 (23:41 +0100)]
Optimise handling of select() returning <= 0.

Before, we immediately retried select() if it returned -1 and errno is EAGAIN
or EINTR, and if it returned 0 it would check for network events even if we
know there are none.  Now, if -1 or 0 is returned we skip checking network
events, but we do check for timer and signal events.

14 years agoPing nodes immediately when receiving SIGALRM.
Guus Sliepen [Fri, 15 Jan 2010 22:19:08 +0000 (23:19 +0100)]
Ping nodes immediately when receiving SIGALRM.

One reason to send the ALRM signal is to let tinc immediately try to connect to
outgoing nodes, for example when PPP or DHCP configuration of the outgoing
interface finished.  Conversely, when the outgoing interface goes down one can
now send this signal to let tinc quickly detect that links are down too.

14 years agoClamp MSS of IPv4 SYN packets.
Guus Sliepen [Fri, 15 Jan 2010 12:42:37 +0000 (13:42 +0100)]
Clamp MSS of IPv4 SYN packets.

Some ISPs block the ICMP Fragmentation Needed packets that tinc sends.  We
clamp the MSS of IPv4 SYN packets to prevent hosts behind those ISPs from
sending too large packets.

14 years agoMove source from lib/ to src/.
Guus Sliepen [Thu, 31 Dec 2009 12:19:13 +0000 (13:19 +0100)]
Move source from lib/ to src/.

The utility functions in the lib/ directory do not really form a library.
Also, now that we build two binaries, tincctl does not need everything that was
in libvpn.a, so it is wasteful to link to it.

14 years agoRemove unused AVL tree library.
Guus Sliepen [Thu, 31 Dec 2009 12:09:14 +0000 (13:09 +0100)]
Remove unused AVL tree library.

14 years agoAllow Port and PMTUDiscovery options in tinc.conf, always enable PMTUDiscovery by...
Guus Sliepen [Thu, 24 Dec 2009 11:42:21 +0000 (12:42 +0100)]
Allow Port and PMTUDiscovery options in tinc.conf, always enable PMTUDiscovery by default.

14 years agoUse xstrdup() instead of xasprintf() to copy static strings.
Guus Sliepen [Wed, 23 Dec 2009 18:51:55 +0000 (19:51 +0100)]
Use xstrdup() instead of xasprintf() to copy static strings.

14 years agoAllow port to be specified in Address statements.
Guus Sliepen [Wed, 23 Dec 2009 18:49:38 +0000 (19:49 +0100)]
Allow port to be specified in Address statements.

This allows one to connect to use more than one port number to connect to
another node. The syntax is now:

Address = <hostname> [<port>]

14 years agoDo not fragment packets smaller than RFC defined minimum MTUs.
Guus Sliepen [Wed, 23 Dec 2009 18:22:06 +0000 (19:22 +0100)]
Do not fragment packets smaller than RFC defined minimum MTUs.

For IPv6, the minimum MTU is 1280 (RFC 2460), for IPv4 the minimum is actually
68, but this is such a low limit that it will probably hurt performance, so we
do as if it is 576 (the minimum packet size hosts should be able to handle, RFC
791). If we detect a path MTU smaller than those minima, and we have to handle
a packet that is bigger than the PMTU but smaller than those minima, we forward
them via TCP instead of fragmenting or returning ICMP packets.

14 years agoDo not use hardcoded cipher block length when padding.
Guus Sliepen [Sat, 19 Dec 2009 22:23:25 +0000 (23:23 +0100)]
Do not use hardcoded cipher block length when padding.

14 years agoFix alignment of results of RSA operations when using libgcrypt.
Guus Sliepen [Sat, 19 Dec 2009 21:17:39 +0000 (22:17 +0100)]
Fix alignment of results of RSA operations when using libgcrypt.

If the result of an RSA encryption or decryption operation can be represented
in less bytes than given, gcry_mpi_print() will not add leading zero bytes. Fix
this by adding those ourself.

14 years agoDo not consider unreachable nodes when trying to determine packet origin.
Guus Sliepen [Sat, 19 Dec 2009 19:53:48 +0000 (20:53 +0100)]
Do not consider unreachable nodes when trying to determine packet origin.

14 years agorecv() and recvfrom() return int, do not prematurely cast the return value.
Guus Sliepen [Sat, 19 Dec 2009 19:52:19 +0000 (20:52 +0100)]
recv() and recvfrom() return int, do not prematurely cast the return value.

14 years agoFix reading raw RSA keys with libgcrypt.
Guus Sliepen [Sat, 19 Dec 2009 19:26:30 +0000 (20:26 +0100)]
Fix reading raw RSA keys with libgcrypt.

14 years agoReinitialise block cipher IV each time we encrypt a packet when using libgcrypt.
Guus Sliepen [Sat, 19 Dec 2009 19:10:38 +0000 (20:10 +0100)]
Reinitialise block cipher IV each time we encrypt a packet when using libgcrypt.

14 years agoFix block cipher padding when using libgcrypt.
Guus Sliepen [Sat, 19 Dec 2009 17:57:54 +0000 (18:57 +0100)]
Fix block cipher padding when using libgcrypt.

14 years agoFix packet authentication.
Guus Sliepen [Fri, 18 Dec 2009 00:15:25 +0000 (01:15 +0100)]
Fix packet authentication.

This wasn't working at all, since we didn't do HMAC but just a plain hash.
Also, verification of packets failed because it was checking the whole packet,
not the packet minus the HMAC.

14 years agoStart of a GUI for tinc.
Guus Sliepen [Wed, 16 Dec 2009 20:18:21 +0000 (21:18 +0100)]
Start of a GUI for tinc.

14 years agoAllow connections to be closed.
Guus Sliepen [Wed, 16 Dec 2009 20:16:56 +0000 (21:16 +0100)]
Allow connections to be closed.

This only closes existing meta connections, it may not affect node
reachability.

14 years agoInclude missing header files and source directories.
Guus Sliepen [Mon, 14 Dec 2009 20:25:06 +0000 (21:25 +0100)]
Include missing header files and source directories.

14 years agoDo not include OpenSSL headers directly.
Guus Sliepen [Mon, 14 Dec 2009 20:20:56 +0000 (21:20 +0100)]
Do not include OpenSSL headers directly.

14 years agoFix compiler warnings.
Guus Sliepen [Fri, 11 Dec 2009 21:38:06 +0000 (22:38 +0100)]
Fix compiler warnings.

14 years agoMerge branch 'master' into 1.1
Guus Sliepen [Fri, 11 Dec 2009 21:31:27 +0000 (22:31 +0100)]
Merge branch 'master' into 1.1

Conflicts:
src/subnet.c

14 years agoOnly call ioctlsocket() on Windows.
Guus Sliepen [Fri, 11 Dec 2009 21:24:07 +0000 (22:24 +0100)]
Only call ioctlsocket() on Windows.

14 years agoForget addresses of unreachable nodes.
Guus Sliepen [Tue, 8 Dec 2009 22:18:37 +0000 (22:18 +0000)]
Forget addresses of unreachable nodes.

We clear the cached address used for UDP connections when a node becomes
unreachable. This also prevents host-up scripts from passing the old, cached
address from when the host becomes reachable again from a different address.

14 years agoRemove unused variable in lookup_subnet_*() functions.
Guus Sliepen [Sat, 28 Nov 2009 11:56:13 +0000 (11:56 +0000)]
Remove unused variable in lookup_subnet_*() functions.

14 years agoWhen learning MAC addresses, only check our own Subnets for previous entries.
Guus Sliepen [Sat, 28 Nov 2009 11:52:23 +0000 (11:52 +0000)]
When learning MAC addresses, only check our own Subnets for previous entries.

Before it would check all addresses, and not learn an address if another node
already claimed that address. This caused fast roaming to fail, the code from
commit 6f6f426b353596edca77829c0477268fc2fc1925 was never triggered.

14 years agoUse the TCP socket infrastructure for control sockets.
Guus Sliepen [Sat, 7 Nov 2009 22:43:25 +0000 (23:43 +0100)]
Use the TCP socket infrastructure for control sockets.

The control socket code was completely different from how meta connections are
handled, resulting in lots of extra code to handle requests.  Also, not every
operating system has UNIX sockets, so we have to resort to another type of
sockets or pipes for those anyway.  To reduce code duplication and make control
sockets work the same on all platforms, we now just connect to the TCP port
where tincd is already listening on.

To authenticate, the program that wants to control a running tinc daemon must
send the contents of a cookie file. The cookie is a random 256 bits number that
is regenerated every time tincd starts. The cookie file should only be readable
by the same user that can start a tincd.

Instead of the binary-ish protocol previously used, we now use an ASCII
protocol similar to that of the meta connections, but this can still change.

14 years agoSmall fixes to get really working control sockets on Windows.
Guus Sliepen [Sat, 7 Nov 2009 15:09:56 +0000 (16:09 +0100)]
Small fixes to get really working control sockets on Windows.

14 years agoBetter integration of libevent in build system.
Guus Sliepen [Sat, 7 Nov 2009 13:35:48 +0000 (14:35 +0100)]
Better integration of libevent in build system.

Since event.h is not part of tinc, we include it in have.h were all other
system header files are included.  We also ensure -levent comes before -lgdi32
when compiling with MinGW, apparently it doesn't work when the order is
reversed.

14 years agoMake sure the 1.1 branch compiles in a MinGW environment.
Guus Sliepen [Thu, 5 Nov 2009 22:29:28 +0000 (23:29 +0100)]
Make sure the 1.1 branch compiles in a MinGW environment.

UNIX domain sockets, of course, don't exist on Windows. For now, when compiling
tinc in a MinGW environment, try to use a TCP socket bound to localhost as an
alternative.

14 years agoHandle PKCS#5 padding in the gcrypt backend.
Guus Sliepen [Wed, 4 Nov 2009 23:02:42 +0000 (00:02 +0100)]
Handle PKCS#5 padding in the gcrypt backend.

14 years agoHandle truncated message authentication codes with gcrypt.
Guus Sliepen [Wed, 4 Nov 2009 23:01:25 +0000 (00:01 +0100)]
Handle truncated message authentication codes with gcrypt.

Commit 4124b9682f8f890acb25d0c92f2583eef670274a did not update the gcrypt
backend.

14 years agoUse %x instead of %lx where appropriate.
Guus Sliepen [Wed, 4 Nov 2009 15:19:08 +0000 (16:19 +0100)]
Use %x instead of %lx where appropriate.

Some conversions were not properly merged from the master branch.

14 years agoDon't enable device events when there is no valid filedescriptor.
Guus Sliepen [Wed, 4 Nov 2009 15:18:08 +0000 (16:18 +0100)]
Don't enable device events when there is no valid filedescriptor.

14 years agoMerge branch 'master' into 1.1
Guus Sliepen [Mon, 2 Nov 2009 13:24:27 +0000 (14:24 +0100)]
Merge branch 'master' into 1.1

Conflicts:
NEWS
README
configure.in
doc/tinc.texi
doc/tincd.8.in
src/Makefile.am
src/connection.c
src/edge.c
src/meta.c
src/net.c
src/net.h
src/net_packet.c
src/net_setup.c
src/net_socket.c
src/node.c
src/openssl/rsagen.h
src/protocol_auth.c
src/protocol_edge.c
src/subnet.c

14 years agoReleasing 1.0.11. release-1.0.11
Guus Sliepen [Sun, 1 Nov 2009 15:24:39 +0000 (16:24 +0100)]
Releasing 1.0.11.

14 years agoStart a tinc service if it already exists.
Guus Sliepen [Sun, 1 Nov 2009 14:57:28 +0000 (15:57 +0100)]
Start a tinc service if it already exists.

14 years agoFast handoff of roaming MAC addresses.
Guus Sliepen [Tue, 27 Oct 2009 22:53:49 +0000 (23:53 +0100)]
Fast handoff of roaming MAC addresses.

In switch mode, if a known MAC address is claimed by a second node before it
expired at the first node, it is likely that this is because a computer has
roamed from the LAN of the first node to that of the second node. To ensure
packets for that computer are routed to the second node, the first node should
delete its corresponding Subnet as soon as possible, without waiting for the
normal expiry timeout.

14 years agoMove socket error interpretation to utils.h.
Guus Sliepen [Sat, 24 Oct 2009 23:40:07 +0000 (01:40 +0200)]
Move socket error interpretation to utils.h.

14 years agoUse WSAGetLastError() to determine cause of network errors on Windows.
Guus Sliepen [Sat, 24 Oct 2009 22:50:09 +0000 (00:50 +0200)]
Use WSAGetLastError() to determine cause of network errors on Windows.

This reduces log spam and lets path MTU discovery work faster.

14 years agoRemove localedir leftovers.
Michael Tokarev [Sun, 18 Oct 2009 17:27:24 +0000 (21:27 +0400)]
Remove localedir leftovers.

14 years agoUse IP_DONTFRAGMENT instead of IP_MTU_DISCOVER on Windows.
Guus Sliepen [Sat, 24 Oct 2009 20:32:35 +0000 (22:32 +0200)]
Use IP_DONTFRAGMENT instead of IP_MTU_DISCOVER on Windows.

This ensures the DF bit on outgoing UDP packets gets set on Windows when path
MTU discovery is enabled, reducing fragmentation.

14 years agoForward packets to not directly reachable hosts via UDP if possible.
Guus Sliepen [Sat, 24 Oct 2009 19:53:01 +0000 (21:53 +0200)]
Forward packets to not directly reachable hosts via UDP if possible.

If MTU probing discovered a node was not reachable via UDP, packets for it were
forwarded to the next hop, but always via TCP, even if the next hop was
reachable via UDP. This is now fixed by retrying to send the packet using
send_packet() if the destination is not the same as the nexthop.

14 years agoMake maxmtu equal to minmtu when fixing the path MTU to a node.
Guus Sliepen [Sat, 24 Oct 2009 19:35:40 +0000 (21:35 +0200)]
Make maxmtu equal to minmtu when fixing the path MTU to a node.

This ensures MTU probes used to ping nodes are not too large, and prevents
restarting MTU probing unnecessarily.

14 years agoAlways reply to MTU probes via UDP.
Guus Sliepen [Sat, 24 Oct 2009 19:32:06 +0000 (21:32 +0200)]
Always reply to MTU probes via UDP.

It could sometime happen that a node would return MTU probes via TCP, which
does not make a lot of sense.

14 years agoAllow UDP packets with an address different from the corresponding TCP connection.
Guus Sliepen [Sat, 24 Oct 2009 18:54:44 +0000 (20:54 +0200)]
Allow UDP packets with an address different from the corresponding TCP connection.

14 years agoUse uint32_t instead of long int for connection options.
Guus Sliepen [Sat, 24 Oct 2009 14:15:24 +0000 (16:15 +0200)]
Use uint32_t instead of long int for connection options.

Options should have a fixed width anyway, but this also fixes a possible MinGW
compiler bug where %lx tries to print a 64 bit value, even though a long int is
only 32 bits.

14 years agoAdd dummy device.
Guus Sliepen [Sat, 24 Oct 2009 14:05:12 +0000 (16:05 +0200)]
Add dummy device.

14 years agoClarify and increase level of log message about MTU probes to unreachable nodes.
Guus Sliepen [Tue, 20 Oct 2009 20:39:07 +0000 (22:39 +0200)]
Clarify and increase level of log message about MTU probes to unreachable nodes.

14 years agoHandle weighted Subnets in switch and hub modes.
Guus Sliepen [Tue, 20 Oct 2009 20:33:16 +0000 (22:33 +0200)]
Handle weighted Subnets in switch and hub modes.

We now handle MAC Subnets in exactly the same way as IPv4 and IPv6 Subnets.
This also fixes a problem that causes unncessary broadcasting of unicast
packets in VPNs where some daemons run 1.0.10 and some run other versions.

14 years agoStarting to work towards 1.0.11.
Guus Sliepen [Tue, 20 Oct 2009 20:22:59 +0000 (22:22 +0200)]
Starting to work towards 1.0.11.

14 years agoFix a possible crash when sending the HUP signal.
Guus Sliepen [Tue, 20 Oct 2009 20:14:47 +0000 (22:14 +0200)]
Fix a possible crash when sending the HUP signal.

When the HUP signal is sent while some outgoing connections have not been made
yet, or are being retried, a NULL pointer could be dereferenced resulting in
tinc crashing. We fix this by more careful handling of outgoing_ts, and by
deleting all connections that have not been fully activated yet at the HUP
signal is received.

14 years agoReleasing 1.0.10. release-1.0.10
Guus Sliepen [Sun, 18 Oct 2009 14:45:13 +0000 (16:45 +0200)]
Releasing 1.0.10.

14 years agoFix description of the WEIGHT environment variable.
Guus Sliepen [Sun, 18 Oct 2009 14:44:32 +0000 (16:44 +0200)]
Fix description of the WEIGHT environment variable.

14 years agoInclude missing header.
Guus Sliepen [Sun, 18 Oct 2009 12:22:20 +0000 (14:22 +0200)]
Include missing header.

14 years agoRemove debugging message when reading packets from a BSD device.
Guus Sliepen [Mon, 12 Oct 2009 21:51:57 +0000 (23:51 +0200)]
Remove debugging message when reading packets from a BSD device.

This was inadvertently introduced by commit
4a5d42178cc0954efba8b24058da9c70cc77c35a.

14 years agoAllow the cloning /dev/tap interface to be used on FreeBSD and NetBSD.
Guus Sliepen [Mon, 12 Oct 2009 20:14:47 +0000 (22:14 +0200)]
Allow the cloning /dev/tap interface to be used on FreeBSD and NetBSD.

This device works like /dev/tun on Linux, automatically creating a new tap
interface when a program opens it. We now pass the actual name of the newly
created interface in $INTERFACE.

14 years agoUse MTU probes to regularly ping other nodes over UDP.
Guus Sliepen [Sun, 11 Oct 2009 16:57:58 +0000 (18:57 +0200)]
Use MTU probes to regularly ping other nodes over UDP.

This keeps NAT mappings for UDP alive, and will also detect when a node is not
reachable via UDP anymore or if the path MTU is decreasing. Tinc will fall back
to TCP if the node has become unreachable.

If UDP communication is impossible, we stop sending probes, but we retry if it
changes its keys.

We also decouple the UDP and TCP ping mechanisms completely, to ensure tinc
properly detects failure of either method.

14 years agoSmall updates to the documentation.
Guus Sliepen [Sun, 11 Oct 2009 13:46:52 +0000 (15:46 +0200)]
Small updates to the documentation.

Mention that TCPOnly is not necessary anymore since tinc will autodetect
whether it can send via UDP or not. Also mention the WEIGHT environment
variable and the new default value (2048 bits) of RSA keys.

14 years agoEnsure that the texinfo manual can be converted to HTML.
Guus Sliepen [Sun, 11 Oct 2009 12:20:14 +0000 (14:20 +0200)]
Ensure that the texinfo manual can be converted to HTML.

The top node was made conditional with the @iftex command, since it should not
appear in PostScript and PDF output. However, it is still necessary for
texi2html, so we have to use @ifnottex instead.

Texi2html also complains about the use of @cindex in the copyright statement,
so we remove that.

14 years agoRevert "Raise default crypto algorithms to AES256 and SHA256."
Guus Sliepen [Sun, 11 Oct 2009 11:56:04 +0000 (13:56 +0200)]
Revert "Raise default crypto algorithms to AES256 and SHA256."

Although it would be better to have the new defaults, only the most recent
releases of most of the platforms supported by tinc come with a version of
OpenSSL that supports SHA256. To ensure people can compile tinc and that nodes
can interact with each other, we revert the default back to Blowfish and SHA1.

This reverts commit 4bb3793e38b7c7f24dd308801e7f6dbb02cf02d2.

14 years agoRemove code duplication when checking ADD_EDGE/DEL_EDGE messages.
Guus Sliepen [Sun, 11 Oct 2009 11:54:05 +0000 (13:54 +0200)]
Remove code duplication when checking ADD_EDGE/DEL_EDGE messages.

14 years agoDon't disconnect clients in TunnelServer mode who send unauthorised ADD_SUBNETs.
Guus Sliepen [Sun, 11 Oct 2009 11:51:10 +0000 (13:51 +0200)]
Don't disconnect clients in TunnelServer mode who send unauthorised ADD_SUBNETs.

So that we are liberal in what we accept.

14 years agoRemoved last gettext function.
Borg [Sat, 3 Oct 2009 11:06:00 +0000 (13:06 +0200)]
Removed last gettext function.

14 years agoRemove autogenerated files from EXTRA_DIST.
Guus Sliepen [Tue, 29 Sep 2009 14:25:20 +0000 (16:25 +0200)]
Remove autogenerated files from EXTRA_DIST.

Apparently they were once necessary, but autoconf now includes them
automatically.  Some of them are not used anymore, and this caused make dist to
fail.

14 years agoUpdate FSF address in files not covered by the merge.
Guus Sliepen [Tue, 29 Sep 2009 13:33:58 +0000 (15:33 +0200)]
Update FSF address in files not covered by the merge.

14 years agoDrop localisation and checkpoint tracing in files not covered by the merge.
Guus Sliepen [Tue, 29 Sep 2009 13:19:55 +0000 (15:19 +0200)]
Drop localisation and checkpoint tracing in files not covered by the merge.

14 years agoMerge branch 'master' into 1.1
Guus Sliepen [Tue, 29 Sep 2009 12:55:29 +0000 (14:55 +0200)]
Merge branch 'master' into 1.1

Conflicts:
NEWS
configure.in
lib/Makefile.am
lib/pidfile.c
lib/pidfile.h
lib/utils.c
po/POTFILES.in
po/nl.po
src/Makefile.am
src/bsd/device.c
src/conf.c
src/connection.c
src/cygwin/device.c
src/edge.c
src/event.c
src/graph.c
src/linux/device.c
src/meta.c
src/mingw/device.c
src/net.c
src/net_packet.c
src/net_setup.c
src/net_socket.c
src/netutl.c
src/node.c
src/process.c
src/protocol.c
src/protocol_auth.c
src/protocol_edge.c
src/protocol_key.c
src/protocol_misc.c
src/protocol_subnet.c
src/raw_socket/device.c
src/route.c
src/solaris/device.c
src/subnet.c
src/tincd.c
src/uml_socket/device.c

14 years agoUpdate the NEWS.
Guus Sliepen [Sat, 26 Sep 2009 10:51:52 +0000 (12:51 +0200)]
Update the NEWS.

14 years agoAdd more authors to the copyright headers.
Guus Sliepen [Fri, 25 Sep 2009 19:14:56 +0000 (21:14 +0200)]
Add more authors to the copyright headers.

Git's log and blame tools were used to find out which files had significant
contributions from authors who sent in patches that were applied before we used
git.

14 years agoDrop support for localisation.
Guus Sliepen [Thu, 24 Sep 2009 22:54:07 +0000 (00:54 +0200)]
Drop support for localisation.

Localised messages don't make much sense for a daemon, and there is only the
Dutch translation which costs time to maintain.

14 years agoRemove checkpoint tracing.
Guus Sliepen [Thu, 24 Sep 2009 22:33:04 +0000 (00:33 +0200)]
Remove checkpoint tracing.

This feature is not necessary anymore since we have tools like valgrind today
that can catch stack overflow errors before they make a backtrace in gdb
impossible.

14 years agoK&R style braces.
Guus Sliepen [Thu, 24 Sep 2009 22:14:03 +0000 (00:14 +0200)]
K&R style braces.

This is essentially commit f02d3ed3e135b5326003e7f69f8331ff6a3cc219 from the
1.1 branch, making it easier to merge between master and 1.1.

14 years agoUpdate the address of the Free Software Foundation in all copyright headers.
Guus Sliepen [Thu, 24 Sep 2009 22:01:00 +0000 (00:01 +0200)]
Update the address of the Free Software Foundation in all copyright headers.

14 years agoRemove Ivo's old email addresses.
Guus Sliepen [Thu, 24 Sep 2009 21:42:30 +0000 (23:42 +0200)]
Remove Ivo's old email addresses.

14 years agoRemove all occurences of $Id$.
Guus Sliepen [Thu, 24 Sep 2009 21:39:16 +0000 (23:39 +0200)]
Remove all occurences of $Id$.

14 years agoUpdate copyright information.
Guus Sliepen [Thu, 24 Sep 2009 21:29:46 +0000 (23:29 +0200)]
Update copyright information.

- Update year numbers in copyright headers.
- Add copyright information for Michael Tokarev and Florian Forster to the
  copyright headers of files to which they have contributed significantly.
- Mention Michael and Florian in AUTHORS.
- Mention that tinc is GPLv3 or later if compiled with the --enable-tunemu
  flag.

14 years agoAdd a better autoconf check for libevent.
Guus Sliepen [Wed, 16 Sep 2009 21:43:19 +0000 (23:43 +0200)]
Add a better autoconf check for libevent.

14 years agoReplace asprintf()s not covered by the merge to xasprintf().
Guus Sliepen [Wed, 16 Sep 2009 18:28:30 +0000 (20:28 +0200)]
Replace asprintf()s not covered by the merge to xasprintf().

14 years agoUse correct format specifiers.
Guus Sliepen [Wed, 16 Sep 2009 18:17:11 +0000 (20:17 +0200)]
Use correct format specifiers.

14 years agoAdd missing #include.
Guus Sliepen [Wed, 16 Sep 2009 18:16:54 +0000 (20:16 +0200)]
Add missing #include.

14 years agoMerge branch 'master' into 1.1
Guus Sliepen [Wed, 16 Sep 2009 17:55:47 +0000 (19:55 +0200)]
Merge branch 'master' into 1.1

Conflicts:
have.h
lib/dropin.c
lib/fake-getaddrinfo.c
lib/pidfile.c
src/Makefile.am
src/bsd/device.c
src/conf.c
src/connection.c
src/connection.h
src/graph.c
src/mingw/device.c
src/net.c
src/net_setup.c
src/node.c
src/protocol_key.c
src/protocol_misc.c
src/tincd.c

14 years agoSend large packets we cannot handle properly via TCP.
Guus Sliepen [Tue, 15 Sep 2009 21:22:13 +0000 (23:22 +0200)]
Send large packets we cannot handle properly via TCP.

During the path MTU discovery phase, we might not know the maximum MTU yet, but
we do know a safe minimum.  If we encounter a packet that is larger than that
the minimum, we now send it via TCP instead to ensure it arrives.  We also
allow large packets that we cannot fragment or create ICMP replies for to be
sent via TCP.

14 years agoRaise default RSA key length to 2048 bits.
Guus Sliepen [Tue, 15 Sep 2009 21:04:52 +0000 (23:04 +0200)]
Raise default RSA key length to 2048 bits.

14 years agoUse a mutex to allow the TAP reader to process packets faster on Windows.
Guus Sliepen [Tue, 15 Sep 2009 20:59:01 +0000 (22:59 +0200)]
Use a mutex to allow the TAP reader to process packets faster on Windows.

The TAP-Win32 device is not a socket, and select() under Windows only works
with sockets.  Tinc used a separate thread to read from the TAP-Win32 device,
and passed this via a local socket to the main thread which could then select()
from it. We now use a global mutex, which is only unlocked when the main thread
is waiting for select(), to allow the TAP reader thread to process packets
directly.

14 years agoRemove extra {.
Guus Sliepen [Tue, 15 Sep 2009 20:58:16 +0000 (22:58 +0200)]
Remove extra {.

14 years agoRaise default crypto algorithms to AES256 and SHA256.
Guus Sliepen [Tue, 15 Sep 2009 10:08:05 +0000 (12:08 +0200)]
Raise default crypto algorithms to AES256 and SHA256.

In light of the recent improvements of attacks on SHA1, the default hash
algorithm in tinc is now SHA256. At the same time, the default symmetric
encryption algorithm has been changed to AES256.

14 years agoUse access() instead of stat() for checking whether scripts exist.
Guus Sliepen [Mon, 14 Sep 2009 22:36:07 +0000 (00:36 +0200)]
Use access() instead of stat() for checking whether scripts exist.

14 years agoRemove dropin random() function, as it is not used anymore.
Guus Sliepen [Mon, 14 Sep 2009 22:28:20 +0000 (00:28 +0200)]
Remove dropin random() function, as it is not used anymore.

14 years agoAllow compiling for Windows XP and higher.
Guus Sliepen [Mon, 14 Sep 2009 22:24:31 +0000 (00:24 +0200)]
Allow compiling for Windows XP and higher.

This allows us to use getaddrinfo(), getnameinfo() and related functions, which
allow tinc to make connections over existing IPv6 networks. These functions are
not available on Windows 2000 however. By default, support is enabled, but when
compiling for Windows 2000 the configure switch --with-windows2000 should be
used.

Since getaddrinfo() et al. are not functions but macros on Windows, we have to
use AC_CHECK_DECLS() instead of AC_CHECK_FUNCS() in configure.in.

14 years agoAlso do not use drand48(), it is not available on Windows.
Guus Sliepen [Mon, 14 Sep 2009 21:28:28 +0000 (23:28 +0200)]
Also do not use drand48(), it is not available on Windows.