2 This file is part of GNUnet
3 (C) 2007, 2009, 2011, 2012 Christian Grothoff
5 GNUnet is free software; you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published
7 by the Free Software Foundation; either version 3, or (at your
8 option) any later version.
10 GNUnet is distributed in the hope that it will be useful, but
11 WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 General Public License for more details.
15 You should have received a copy of the GNU General Public License
16 along with GNUnet; see the file COPYING. If not, write to the
17 Free Software Foundation, Inc., 59 Temple Place - Suite 330,
18 Boston, MA 02111-1307, USA.
22 * @file test_gns_vpn.c
23 * @brief testcase for accessing VPN services via GNS
24 * @author Martin Schanzenbach
27 #include <curl/curl.h>
28 #include <microhttpd.h>
29 #include "gnunet_namestore_service.h"
30 #include "gnunet_gns_service.h"
31 #include "gnunet_testing_lib.h"
34 #define TEST_DOMAIN "www.gnu"
36 #define TIMEOUT GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_SECONDS, 300)
39 * Return value for 'main'.
41 static int global_ret;
43 static struct GNUNET_NAMESTORE_Handle *namestore;
45 static struct MHD_Daemon *mhd;
47 static GNUNET_SCHEDULER_TaskIdentifier mhd_task_id;
49 static GNUNET_SCHEDULER_TaskIdentifier curl_task_id;
58 * IP address of the ultimate destination.
60 static const char *dest_ip;
63 * Address family of the dest_ip.
68 * Address family to use by the curl client.
81 static struct CBC cbc;
85 copy_buffer (void *ptr, size_t size, size_t nmemb, void *ctx)
87 struct CBC *cbc = ctx;
89 if (cbc->pos + size * nmemb > sizeof(cbc->buf))
90 return 0; /* overflow */
91 memcpy (&cbc->buf[cbc->pos], ptr, size * nmemb);
92 cbc->pos += size * nmemb;
99 struct MHD_Connection *connection,
103 const char *upload_data, size_t *upload_data_size,
107 struct MHD_Response *response;
110 if (0 != strcmp ("GET", method))
111 return MHD_NO; /* unexpected method */
118 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "MHD sends respose for request to URL `%s'\n", url);
119 response = MHD_create_response_from_buffer (strlen (url),
121 MHD_RESPMEM_MUST_COPY);
122 ret = MHD_queue_response (connection, MHD_HTTP_OK, response);
123 MHD_destroy_response (response);
133 if (mhd_task_id != GNUNET_SCHEDULER_NO_TASK)
135 GNUNET_SCHEDULER_cancel (mhd_task_id);
136 mhd_task_id = GNUNET_SCHEDULER_NO_TASK;
138 if (curl_task_id != GNUNET_SCHEDULER_NO_TASK)
140 GNUNET_SCHEDULER_cancel (curl_task_id);
141 curl_task_id = GNUNET_SCHEDULER_NO_TASK;
145 MHD_stop_daemon (mhd);
148 GNUNET_free_non_null (url);
154 * Function to run the HTTP client.
161 curl_task (void *cls,
162 const struct GNUNET_SCHEDULER_TaskContext *tc)
164 curl_task_id = GNUNET_SCHEDULER_NO_TASK;
176 struct GNUNET_NETWORK_FDSet nrs;
177 struct GNUNET_NETWORK_FDSet nws;
178 struct GNUNET_TIME_Relative delay;
187 curl_multi_perform (multi, &running);
190 GNUNET_assert (NULL != (msg = curl_multi_info_read (multi, &running)));
191 if (msg->msg == CURLMSG_DONE)
193 if (msg->data.result != CURLE_OK)
196 "%s failed at %s:%d: `%s'\n",
197 "curl_multi_perform",
199 __LINE__, curl_easy_strerror (msg->data.result));
203 curl_multi_remove_handle (multi, curl);
204 curl_multi_cleanup (multi);
205 curl_easy_cleanup (curl);
208 if (cbc.pos != strlen ("/hello_world"))
213 if (0 != strncmp ("/hello_world", cbc.buf, strlen ("/hello_world")))
218 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Download complete, shutting down!\n");
222 GNUNET_assert (CURLM_OK == curl_multi_fdset (multi, &rs, &ws, &es, &max));
223 if ( (CURLM_OK != curl_multi_timeout (multi, &timeout)) ||
225 delay = GNUNET_TIME_UNIT_SECONDS;
227 delay = GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_MILLISECONDS, (unsigned int) timeout);
228 GNUNET_NETWORK_fdset_copy_native (&nrs,
231 GNUNET_NETWORK_fdset_copy_native (&nws,
234 curl_task_id = GNUNET_SCHEDULER_add_select (GNUNET_SCHEDULER_PRIORITY_DEFAULT,
244 start_curl (void *cls, const struct GNUNET_SCHEDULER_TaskContext *tc)
246 GNUNET_asprintf (&url,
247 "http://%s/hello_world",
249 curl = curl_easy_init ();
250 curl_easy_setopt (curl, CURLOPT_URL, url);
251 curl_easy_setopt (curl, CURLOPT_WRITEFUNCTION, ©_buffer);
252 curl_easy_setopt (curl, CURLOPT_WRITEDATA, &cbc);
253 curl_easy_setopt (curl, CURLOPT_FAILONERROR, 1);
254 curl_easy_setopt (curl, CURLOPT_TIMEOUT, 150L);
255 curl_easy_setopt (curl, CURLOPT_CONNECTTIMEOUT, 15L);
256 curl_easy_setopt (curl, CURLOPT_NOSIGNAL, 1);
258 multi = curl_multi_init ();
259 GNUNET_assert (multi != NULL);
260 GNUNET_assert (CURLM_OK == curl_multi_add_handle (multi, curl));
261 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Beginning HTTP download from `%s'\n", url);
267 disco_ns (void* cls, const struct GNUNET_SCHEDULER_TaskContext *tc)
269 GNUNET_NAMESTORE_disconnect (namestore);
275 * Callback invoked from the namestore service once record is
279 * @param af address family, AF_INET or AF_INET6; AF_UNSPEC on error;
280 * will match 'result_af' from the request
281 * @param address IP address (struct in_addr or struct in_addr6, depending on 'af')
282 * that the VPN allocated for the redirection;
283 * traffic to this IP will now be redirected to the
284 * specified target peer; NULL on error
287 commence_testing (void *cls, int32_t success, const char *emsg)
289 GNUNET_SCHEDULER_add_now (&disco_ns, NULL);
291 if ((emsg != NULL) && (GNUNET_YES != success))
294 "NS failed to create record %s\n", emsg);
295 GNUNET_SCHEDULER_shutdown ();
298 GNUNET_SCHEDULER_add_delayed (GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_SECONDS, 10), &start_curl, NULL);
303 * Function to keep the HTTP server running.
311 const struct GNUNET_SCHEDULER_TaskContext *tc)
313 mhd_task_id = GNUNET_SCHEDULER_NO_TASK;
322 struct GNUNET_NETWORK_FDSet nrs;
323 struct GNUNET_NETWORK_FDSet nws;
328 unsigned MHD_LONG_LONG timeout;
329 struct GNUNET_TIME_Relative delay;
331 GNUNET_assert (GNUNET_SCHEDULER_NO_TASK == mhd_task_id);
336 GNUNET_assert (MHD_YES ==
337 MHD_get_fdset (mhd, &rs, &ws, &es, &max_fd));
338 if (MHD_YES == MHD_get_timeout (mhd, &timeout))
339 delay = GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_MILLISECONDS,
340 (unsigned int) timeout);
342 delay = GNUNET_TIME_UNIT_FOREVER_REL;
343 GNUNET_NETWORK_fdset_copy_native (&nrs,
346 GNUNET_NETWORK_fdset_copy_native (&nws,
349 mhd_task_id = GNUNET_SCHEDULER_add_select (GNUNET_SCHEDULER_PRIORITY_DEFAULT,
360 const struct GNUNET_CONFIGURATION_Handle *cfg,
361 struct GNUNET_TESTING_Peer *peer)
364 struct GNUNET_PeerIdentity id;
365 struct GNUNET_CRYPTO_HashAsciiEncoded peername;
366 struct GNUNET_CRYPTO_EddsaPrivateKey *host_key;
367 struct GNUNET_GNSRECORD_Data rd;
371 GNUNET_TESTING_peer_get_identity (peer, &id);
372 GNUNET_CRYPTO_hash_to_enc ((struct GNUNET_HashCode*)&id, &peername);
374 namestore = GNUNET_NAMESTORE_connect (cfg);
375 GNUNET_assert (NULL != namestore);
376 flags = MHD_USE_DEBUG;
377 //if (GNUNET_YES == use_v6)
378 // flags |= MHD_USE_IPv6;
379 mhd = MHD_start_daemon (flags,
384 GNUNET_assert (NULL != mhd);
387 if (GNUNET_OK != GNUNET_CONFIGURATION_get_value_filename (cfg, "gns",
391 GNUNET_log(GNUNET_ERROR_TYPE_ERROR, "Failed to get key from cfg\n");
395 host_key = GNUNET_CRYPTO_eddsa_key_create_from_file (zone_keyfile);
396 rd.expiration_time = GNUNET_TIME_UNIT_FOREVER_ABS.abs_value_us;
397 GNUNET_asprintf (&rd_string, "6 %s %s", (char*)&peername, "www.gnu.");
398 GNUNET_assert (GNUNET_OK == GNUNET_GNSRECORD_string_to_value (GNUNET_GNSRECORD_TYPE_VPN,
402 rd.record_type = GNUNET_GNSRECORD_TYPE_VPN;
404 GNUNET_NAMESTORE_records_store (namestore,
410 GNUNET_free ((void**)rd.data);
411 GNUNET_free (rd_string);
412 GNUNET_free (zone_keyfile);
413 GNUNET_free (host_key);
418 * Open '/dev/null' and make the result the given
421 * @param target_fd desired FD to point to /dev/null
422 * @param flags open flags (O_RDONLY, O_WRONLY)
425 open_dev_null (int target_fd,
430 fd = open ("/dev/null", flags);
435 if (-1 == dup2 (fd, target_fd))
445 * Run the given command and wait for it to complete.
447 * @param file name of the binary to run
448 * @param cmd command line arguments (as given to 'execv')
449 * @return 0 on success, 1 on any error
452 fork_and_exec (const char *file,
469 /* we are the child process */
470 /* close stdin/stdout to not cause interference
471 with the helper's main protocol! */
473 open_dev_null (0, O_RDONLY);
475 open_dev_null (1, O_WRONLY);
476 (void) execv (file, cmd);
477 /* can only get here on error */
479 "exec `%s' failed: %s\n",
484 /* keep running waitpid as long as the only error we get is 'EINTR' */
485 while ( (-1 == (ret = waitpid (pid, &status, 0))) &&
490 "waitpid failed: %s\n",
494 if (! (WIFEXITED (status) && (0 == WEXITSTATUS (status))))
496 /* child process completed and returned success, we're happy */
501 main (int argc, char *const *argv)
507 char *const iptables_args[] =
509 "iptables", "-t", "mangle", "-L", "-v", NULL
512 if (0 == access ("/sbin/iptables", X_OK))
513 sbin_iptables = "/sbin/iptables";
514 else if (0 == access ("/usr/sbin/iptables", X_OK))
515 sbin_iptables = "/usr/sbin/iptables";
519 "Executable iptables not found in approved directories: %s, skipping\n",
524 if (0 != fork_and_exec (sbin_iptables, iptables_args))
527 "Failed to run `iptables -t mangle -L -v'. Skipping test.\n");
531 if (0 != ACCESS ("/dev/net/tun", R_OK))
533 GNUNET_log_strerror_file (GNUNET_ERROR_TYPE_ERROR,
537 "WARNING: System unable to run test, skipping.\n");
541 bin_vpn = GNUNET_OS_get_libexec_binary_path ("gnunet-helper-vpn");
542 bin_exit = GNUNET_OS_get_libexec_binary_path ("gnunet-helper-exit");
543 bin_dns = GNUNET_OS_get_libexec_binary_path ("gnunet-helper-dns");
544 if ( (0 != geteuid ()) &&
546 GNUNET_OS_check_helper_binary (bin_vpn, GNUNET_YES, "-d gnunet-vpn - - 169.1.3.3.7 255.255.255.0")) || //ipv4 only please!
548 GNUNET_OS_check_helper_binary (bin_exit, GNUNET_YES, "-d gnunet-vpn - - - 169.1.3.3.7 255.255.255.0")) || //no nat, ipv4 only
550 GNUNET_OS_check_helper_binary (bin_dns, GNUNET_YES, NULL))) ) // TODO: once we have a windows-testcase, add test parameters here
553 "WARNING: gnunet-helper-{exit,vpn,dns} binaries in $PATH are not SUID, refusing to run test (as it would have to fail).\n");
555 "Change $PATH ('.' in $PATH before $GNUNET_PREFIX/bin is problematic) or permissions (run 'make install' as root) to fix this!\n");
556 GNUNET_free (bin_vpn);
557 GNUNET_free (bin_exit);
558 GNUNET_free (bin_dns);
561 GNUNET_free (bin_vpn);
562 GNUNET_free (bin_exit);
563 GNUNET_free (bin_dns);
565 dest_ip = "169.254.86.1";
569 if (GNUNET_OK == GNUNET_NETWORK_test_pf (PF_INET6))
574 if ( (GNUNET_OK != GNUNET_NETWORK_test_pf (src_af)) ||
575 (GNUNET_OK != GNUNET_NETWORK_test_pf (dest_af)) )
578 "Required address families not supported by this system, skipping test.\n");
581 if (0 != curl_global_init (CURL_GLOBAL_WIN32))
583 fprintf (stderr, "failed to initialize curl\n");
586 if (0 != GNUNET_TESTING_peer_run ("test-gnunet-vpn",
590 GNUNET_DISK_directory_remove ("/tmp/gnunet-test-vpn");
594 /* end of test_gns_vpn.c */