along with this program; if not, write to the Free Software
Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
- $Id: protocol.c,v 1.28.4.34 2000/09/22 15:06:28 guus Exp $
+ $Id: protocol.c,v 1.28.4.39 2000/10/14 17:04:15 guus Exp $
*/
#include "config.h"
#include "net.h"
#include "netutl.h"
#include "protocol.h"
+#include "meta.h"
#include "system.h"
return 1;
}
-/* Generic outgoing request routine - takes care of logging and error detection as well */
+/* Generic request routines - takes care of logging and error detection as well */
int send_request(conn_list_t *cl, const char *format, int request, /*args*/ ...)
{
return -1;
}
- if(debug_lvl >= DEBUG_META)
- syslog(LOG_DEBUG, _("Sending %s to %s (%s): %s"), request_name[request],
- cl->name, cl->hostname, buffer);
- else if(debug_lvl >= DEBUG_PROTOCOL)
+ if(debug_lvl >= DEBUG_PROTOCOL)
syslog(LOG_DEBUG, _("Sending %s to %s (%s)"), request_name[request], cl->name, cl->hostname);
+cp
+ return send_meta(cl, buffer, len);
+}
-
- if(cl->status.encryptin)
+int receive_request(conn_list_t *cl)
+{
+ int request;
+cp
+ if(sscanf(cl->buffer, "%d", &request) == 1)
{
- /* FIXME: Do encryption */
+ if((request < 0) || (request > 255) || (request_handlers[request] == NULL))
+ {
+ syslog(LOG_ERR, _("Unknown request from %s (%s)"),
+ cl->name, cl->hostname);
+ return -1;
+ }
+ else
+ {
+ if(debug_lvl > DEBUG_PROTOCOL)
+ syslog(LOG_DEBUG, _("Got %s from %s (%s)"),
+ request_name[request], cl->name, cl->hostname);
+ }
+ if(request_handlers[request](cl))
+ /* Something went wrong. Probably scriptkiddies. Terminate. */
+ {
+ syslog(LOG_ERR, _("Error while processing %s from %s (%s)"),
+ request_name[request], cl->name, cl->hostname);
+ return -1;
+ }
}
-
- if((write(cl->meta_socket, buffer, len)) < 0)
+ else
{
- syslog(LOG_ERR, _("Sending meta data failed: %m"));
+ syslog(LOG_ERR, _("Bogus data received from %s (%s)"),
+ cl->name, cl->hostname);
return -1;
}
-cp
}
/* Connection protocol:
int send_id(conn_list_t *cl)
{
- int x;
- char *optstr;
cp
- x = send_request(cl, "%d %s %d %s", ID, myself->name, myself->protocol_version, optstr=opt2str(myself->options));
- free(optstr);
-cp
- return x;
+ return send_request(cl, "%d %s %d %lx", ID, myself->name, myself->protocol_version, myself->options);
}
int id_h(conn_list_t *cl)
{
conn_list_t *old;
- char *optstr;
cp
- if(sscanf(cl->buffer, "%*d %as %d %as", &cl->name, &cl->protocol_version, &optstr) != 3)
+ if(sscanf(cl->buffer, "%*d %as %d %lx", &cl->name, &cl->protocol_version, &cl->options) != 3)
{
syslog(LOG_ERR, _("Got bad ID from %s"), cl->hostname);
return -1;
return -1;
}
- /* Check if option string is valid */
-
- if((cl->options = str2opt(optstr)) == -1)
- {
- syslog(LOG_ERR, _("Peer %s uses invalid option string"), cl->hostname);
- free(optstr);
- return -1;
- }
-
- free(optstr);
-
/* Check if identity is a valid name */
if(!check_id(cl->name))
/* Load information about peer */
- if(!read_id(cl))
+ if(!read_host_config(cl))
{
syslog(LOG_ERR, _("Peer %s had unknown identity (%s)"), cl->hostname, cl->name);
return -1;
/* Convert the random data to a hexadecimal formatted string */
bin2hex(cl->hischallenge,buffer,CHAL_LENGTH);
- buffer[keylength*2] = '\0';
+ buffer[CHAL_LENGTH*2] = '\0';
/* Send the challenge */
if(sscanf(cl->buffer, "%*d %as", &hishash) != 2)
{
syslog(LOG_ERR, _("Got bad CHAL_REPLY from %s (%s)"), cl->name, cl->hostname);
+ free(hishash);
return -1;
}
if(strlen(hishash) != SHA_DIGEST_LENGTH*2)
{
syslog(LOG_ERR, _("Intruder: wrong challenge reply length from %s (%s)"), cl->name, cl->hostname);
+ free(hishash);
return -1;
}
/* Exchange information about other tinc daemons */
+/* FIXME: reprogram this.
notify_others(cl, NULL, send_add_host);
notify_one(cl);
-
+*/
upstreamindex = 0;
cp
/* Check if subnet string is valid */
- if((subnet = str2net(subnetstr)) == -1)
+ if(!(subnet = str2net(subnetstr)))
{
syslog(LOG_ERR, _("Got bad ADD_SUBNET from %s (%s): invalid subnet string"), cl->name, cl->hostname);
free(name); free(subnetstr);
/* Check if the owner of the new subnet is in the connection list */
- if(!(owner = lookup_id(name))
+ if(!(owner = lookup_id(name)))
{
syslog(LOG_ERR, _("Got ADD_SUBNET for %s from %s (%s) which is not in our connection list"),
name, cl->name, cl->hostname);
}
/* If everything is correct, add the subnet to the list of the owner */
+
+ subnet_add(owner, subnet);
cp
- return subnet_add(owner, subnet);
+ return 0;
}
int send_del_subnet(conn_list_t *cl, conn_list_t *other, subnet_t *subnet)
/* Check if subnet string is valid */
- if((subnet = str2net(subnetstr)) == -1)
+ if(!(subnet = str2net(subnetstr)))
{
syslog(LOG_ERR, _("Got bad DEL_SUBNET from %s (%s): invalid subnet string"), cl->name, cl->hostname);
free(name); free(subnetstr);
/* Check if the owner of the new subnet is in the connection list */
- if(!(owner = lookup_id(name))
+ if(!(owner = lookup_id(name)))
{
syslog(LOG_ERR, _("Got DEL_SUBNET for %s from %s (%s) which is not in our connection list"),
name, cl->name, cl->hostname);
return -1;
}
- /* If everything is correct, add the subnet to the list of the owner */
+ /* If everything is correct, delete the subnet from the list of the owner */
+
+ subnet_del(subnet);
cp
- return subnet_del(owner, subnet);
+ return 0;
}
/* New and closed connections notification */
int send_add_host(conn_list_t *cl, conn_list_t *other)
{
- char *optstr;
- int x;
-cp
- x = send_request(cl, "%d %s %s %lx:%d %s", ADD_HOST,
- myself->name, other->name, other->real_ip, other->port, optstr = opt2str(other->options));
- free(optstr);
cp
- return x;
+ return send_request(cl, "%d %s %s %lx:%d %lx", ADD_HOST,
+ myself->name, other->name, other->address, other->port, other->options);
}
int add_host_h(conn_list_t *cl)
{
- char *optstr;
char *sender;
conn_list_t *old, *new, *hisuplink;
cp
new = new_conn_list();
- if(sscanf(cl->buffer, "%*d %as %as %lx:%d %as", &sender, &new->name, &new->address, &new->port, &optstr) != 5)
+ if(sscanf(cl->buffer, "%*d %as %as %lx:%d %lx", &sender, &new->name, &new->address, &new->port, &new->options) != 5)
{
syslog(LOG_ERR, _("Got bad ADD_HOST from %s (%s)"), cl->name, cl->hostname);
return -1;
}
- /* Check if option string is valid */
-
- if((new->options = str2opt(optstr)) == -1)
- {
- syslog(LOG_ERR, _("Got bad ADD_HOST from %s (%s): invalid option string"), cl->name, cl->hostname);
- free(optstr); free(sender);
- return -1;
- }
-
- free(optstr);
-
/* Check if identity is a valid name */
if(!check_id(new->name) || !check_id(sender))
/* Lookup his uplink */
- if(!(new->hisuplink = lookup_id(sender))
+ if(!(new->hisuplink = lookup_id(sender)))
{
syslog(LOG_ERR, _("Got ADD_HOST from %s (%s) with origin %s which is not in our connection list"),
sender, cl->name, cl->hostname);
/* Fill in more of the new conn_list structure */
- new->hostname = hostlookup(htonl(new->real_ip));
+ new->hostname = hostlookup(htonl(new->address));
/* Check if the new host already exists in the connnection list */
if((old = lookup_id(new->name)))
{
- if((new->real_ip == old->real_ip) && (new->port == old->port))
+ if((new->address == old->address) && (new->port == old->port))
{
if(debug_lvl > DEBUG_CONNECTIONS)
syslog(LOG_NOTICE, _("Got duplicate ADD_HOST for %s (%s) from %s (%s)"),
conn_list_add(conn_list, new);
/* Tell the rest about the new host */
-
+/* FIXME: reprogram this.
notify_others(new, cl, send_add_host);
-
+*/
cp
return 0;
}
int send_del_host(conn_list_t *cl, conn_list_t *other)
{
- char *optstr;
- int x;
-cp
- x = send_request(cl, "%d %s %s %lx:%d %s", DEL_HOST,
- myself->name, other->name, other->real_ip, other->port, optstr = opt2str(other->options));
- free(optstr);
cp
- return x;
+ return send_request(cl, "%d %s %s %lx:%d %lx", DEL_HOST,
+ myself->name, other->name, other->address, other->port, other->options);
}
int del_host_h(conn_list_t *cl)
{
char *name;
char *sender;
- char *opstr;
ip_t address;
port_t port;
int options;
conn_list_t *old, *hisuplink;
cp
- if(sscanf(cl->buffer, "%*d %as %as %lx:%d %as", &sender, &name, &address, &port, &optstr) != 5)
+ if(sscanf(cl->buffer, "%*d %as %as %lx:%d %lx", &sender, &name, &address, &port, &options) != 5)
{
syslog(LOG_ERR, _("Got bad DEL_HOST from %s (%s)"),
cl->name, cl->hostname);
return -1;
}
- /* Check if option string is valid */
-
- if((options = str2opt(optstr)) == -1)
- {
- syslog(LOG_ERR, _("Got bad DEL_HOST from %s (%s): invalid option string"), cl->name, cl->hostname);
- free(optstr); free(sender); free(name);
- return -1;
- }
-
- free(optstr);
-
/* Check if identity is a valid name */
if(!check_id(name) || !check_id(sender))
/* Lookup his uplink */
- if(!(hisuplink = lookup_id(sender))
+ if(!(hisuplink = lookup_id(sender)))
{
syslog(LOG_ERR, _("Got DEL_HOST from %s (%s) with origin %s which is not in our connection list"),
cl->name, cl->hostname, sender);
if(!strcmp(to_id, myself->name))
{
- send_ans_key(myself, from, myself->datakey->key);
+ send_ans_key(myself, from, myself->cipher_pktkey);
}
else
{
return 0;
}
-int send_ans_key(conn_list_t *from, conn_list_t *to, char *datakey)
+int send_ans_key(conn_list_t *from, conn_list_t *to, char *pktkey)
{
cp
return send_request(to->nexthop, "%d %s %s %s", ANS_KEY,
- from->name, to->name, datakey);
+ from->name, to->name, pktkey);
}
int ans_key_h(conn_list_t *cl)
{
- char *from_id, *to_id, *datakey;
+ char *from_id, *to_id, *pktkey;
int keylength;
conn_list_t *from, *to;
cp
- if(sscanf(cl->buffer, "%*d %as %as %as", &from_id, &to_id, &datakey) != 3)
+ if(sscanf(cl->buffer, "%*d %as %as %as", &from_id, &to_id, &pktkey) != 3)
{
syslog(LOG_ERR, _("Got bad ANS_KEY from %s (%s)"),
cl->name, cl->hostname);
{
syslog(LOG_ERR, _("Got ANS_KEY from %s (%s) origin %s which does not exist in our connection list"),
cl->name, cl->hostname, from_id);
- free(from_id); free(to_id); free(datakey);
+ free(from_id); free(to_id); free(pktkey);
return -1;
}
{
/* It is for us, convert it to binary and set the key with it. */
- keylength = strlen(datakey);
+ keylength = strlen(pktkey);
if((keylength%2) || (keylength <= 0))
{
syslog(LOG_ERR, _("Got bad ANS_KEY from %s (%s) origin %s: invalid key"),
cl->name, cl->hostname, from->name);
- free(from_id); free(to_id); free(datakey);
+ free(from_id); free(to_id); free(pktkey);
return -1;
}
keylength /= 2;
- hex2bin(datakey, datakey, keylength);
- BF_set_key(cl->datakey, keylength, datakey);
+ hex2bin(pktkey, pktkey, keylength);
+ BF_set_key(cl->cipher_pktkey, keylength, pktkey);
}
else
{
{
syslog(LOG_ERR, _("Got ANS_KEY from %s (%s) destination %s which does not exist in our connection list"),
cl->name, cl->hostname, to_id);
- free(from_id); free(to_id); free(datakey);
+ free(from_id); free(to_id); free(pktkey);
return -1;
}
- send_ans_key(from, to, datakey);
+ send_ans_key(from, to, pktkey);
}
- free(from_id); free(to_id); free(datakey);
+ free(from_id); free(to_id); free(pktkey);
cp
return 0;
}
-/* Old routines */
-
-/*
- Notify all my direct connections of a new host
- that was added to the vpn, with the exception
- of the source of the announcement.
-*/
-
-int notify_others(conn_list_t *new, conn_list_t *source,
- int (*function)(conn_list_t*, conn_list_t*))
-{
- conn_list_t *p;
-cp
- for(p = conn_list; p != NULL; p = p->next)
- if(p != new && p != source && p->status.meta && p->status.active)
- function(p, new);
-cp
- return 0;
-}
-
-/*
- Notify one connection of everything
- I have connected
-*/
-
-int notify_one(conn_list_t *new)
-{
- conn_list_t *p;
-cp
- for(p = conn_list; p != NULL; p = p->next)
- if(p != new && p->status.active)
- send_add_host(new, p);
-cp
- return 0;
-}
-
-/* "Complete overhaul". */
+/* Jumptable for the request handlers */
int (*request_handlers[])(conn_list_t*) = {
id_h, challenge_h, chal_reply_h, ack_h,
key_changed_h, req_key_h, ans_key_h,
};
+/* Request names */
+
char (*request_name[]) = {
"ID", "CHALLENGE", "CHAL_REPLY", "ACK",
"STATUS", "ERROR", "TERMREQ",
"ADD_SUBNET", "DEL_SUBNET",
"KEY_CHANGED", "REQ_KEY", "ANS_KEY",
};
+
+/* Status strings */
+
+char (*status_text[]) = {
+ "FIXME: status text",
+};
+
+/* Error strings */
+
+char (*error_text[]) = {
+ "FIXME: error text",
+};