Drop packets forwarded via TCP if they are too big (CVE-2013-1428).
[tinc] / src / connection.h
index 1b3ca36..877601f 100644 (file)
@@ -1,7 +1,7 @@
 /*
     connection.h -- header for connection.c
-    Copyright (C) 2000-2003 Guus Sliepen <guus@sliepen.eu.org>,
-                  2000-2003 Ivo Timmermans <ivo@o2w.nl>
+    Copyright (C) 2000-2012 Guus Sliepen <guus@tinc-vpn.org>,
+                  2000-2005 Ivo Timmermans
 
     This program is free software; you can redistribute it and/or modify
     it under the terms of the GNU General Public License as published by
     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
     GNU General Public License for more details.
 
-    You should have received a copy of the GNU General Public License
-    along with this program; if not, write to the Free Software
-    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
-
-    $Id: connection.h,v 1.1.2.34 2003/07/17 15:06:26 guus Exp $
+    You should have received a copy of the GNU General Public License along
+    with this program; if not, write to the Free Software Foundation, Inc.,
+    51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
 */
 
 #ifndef __TINC_CONNECTION_H__
 #include <openssl/evp.h>
 
 #include "avl_tree.h"
-#include "conf.h"
-#include "edge.h"
-#include "list.h"
-#include "net.h"
-#include "node.h"
 
 #define OPTION_INDIRECT                0x0001
 #define OPTION_TCPONLY         0x0002
+#define OPTION_PMTU_DISCOVERY  0x0004
+#define OPTION_CLAMP_MSS       0x0008
 
 typedef struct connection_status_t {
-       int pinged:1;                           /* sent ping */
-       int active:1;                           /* 1 if active.. */
-       int connecting:1;                       /* 1 if we are waiting for a non-blocking connect() to finish */
-       int termreq:1;                          /* the termination of this connection was requested */
-       int remove:1;                           /* Set to 1 if you want this connection removed */
-       int timeout:1;                          /* 1 if gotten timeout */
-       int encryptout:1;                       /* 1 if we can encrypt outgoing traffic */
-       int decryptin:1;                        /* 1 if we have to decrypt incoming traffic */
-       int mst:1;                                      /* 1 if this connection is part of a minimum spanning tree */
-       int unused:18;
+       unsigned int pinged:1;                          /* sent ping */
+       unsigned int active:1;                          /* 1 if active.. */
+       unsigned int connecting:1;                      /* 1 if we are waiting for a non-blocking connect() to finish */
+       unsigned int unused_termreq:1;                  /* the termination of this connection was requested */
+       unsigned int remove:1;                          /* Set to 1 if you want this connection removed */
+       unsigned int timeout:1;                         /* 1 if gotten timeout */
+       unsigned int encryptout:1;                      /* 1 if we can encrypt outgoing traffic */
+       unsigned int decryptin:1;                       /* 1 if we have to decrypt incoming traffic */
+       unsigned int mst:1;                             /* 1 if this connection is part of a minimum spanning tree */
+       unsigned int unused:23;
 } connection_status_t;
 
+#include "edge.h"
+#include "net.h"
+#include "node.h"
+
 typedef struct connection_t {
        char *name;                                     /* name he claims to have */
 
-       sockaddr_t address;                     /* his real (internet) ip */
+       union sockaddr_t address;                       /* his real (internet) ip */
        char *hostname;                         /* the hostname of its real ip */
        int protocol_version;           /* used protocol */
 
        int socket;                                     /* socket used for this connection */
-       long int options;                       /* options for this connection */
-       struct connection_status_t status;      /* status info */
+       uint32_t options;                       /* options for this connection */
+       connection_status_t status;     /* status info */
        int estimated_weight;           /* estimation for the weight of the edge for this connection */
        struct timeval start;           /* time this connection was started, used for above estimation */
        struct outgoing_t *outgoing;    /* used to keep track of outgoing connections */
@@ -90,21 +89,27 @@ typedef struct connection_t {
        int tcplen;                                     /* length of incoming TCPpacket */
        int allow_request;                      /* defined if there's only one request possible */
 
-       time_t last_ping_time;          /* last time we saw some activity from the other end */
+       char *outbuf;                           /* metadata output buffer */
+       int outbufstart;                        /* index of first meaningful byte in output buffer */
+       int outbuflen;                          /* number of meaningful bytes in output buffer */
+       int outbufsize;                         /* number of bytes allocated to output buffer */
+
+       time_t last_ping_time;          /* last time we saw some activity from the other end or pinged them */
+       time_t last_flushed_time;       /* last time buffer was empty. Only meaningful if outbuflen > 0 */
 
        avl_tree_t *config_tree;        /* Pointer to configuration tree belonging to him */
 } connection_t;
 
 extern avl_tree_t *connection_tree;
-extern connection_t *broadcast;
+extern connection_t *everyone;
 
 extern void init_connections(void);
 extern void exit_connections(void);
-extern connection_t *new_connection(void) __attribute__ ((malloc));
+extern connection_t *new_connection(void) __attribute__ ((__malloc__));
 extern void free_connection(connection_t *);
+extern void free_connection_partially(connection_t *);
 extern void connection_add(connection_t *);
 extern void connection_del(connection_t *);
 extern void dump_connections(void);
-extern int read_connection_config(connection_t *);
 
 #endif                                                 /* __TINC_CONNECTION_H__ */