-Stop the vpn-helper if an invalid message arrives
[oweals/gnunet.git] / src / vpn / gnunet-daemon-vpn.c
1 /*
2      This file is part of GNUnet.
3      (C) 2010 Christian Grothoff
4
5      GNUnet is free software; you can redistribute it and/or modify
6      it under the terms of the GNU General Public License as published
7      by the Free Software Foundation; either version 3, or (at your
8      option) any later version.
9
10      GNUnet is distributed in the hope that it will be useful, but
11      WITHOUT ANY WARRANTY; without even the implied warranty of
12      MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
13      General Public License for more details.
14
15      You should have received a copy of the GNU General Public License
16      along with GNUnet; see the file COPYING.  If not, write to the
17      Free Software Foundation, Inc., 59 Temple Place - Suite 330,
18      Boston, MA 02111-1307, USA.
19 */
20
21 /**
22  * @file vpn/gnunet-daemon-vpn.c
23  * @brief 
24  * @author Philipp Tölke
25  */
26 #include "platform.h"
27 #include "gnunet_getopt_lib.h"
28 #include "gnunet_program_lib.h"
29 #include "gnunet_os_lib.h"
30 #include "gnunet-vpn-helper-p.h"
31 #include "gnunet-vpn-packet.h"
32 #include "gnunet-vpn-pretty-print.h"
33 #include "gnunet_common.h"
34 #include "gnunet_protocols.h"
35 #include "gnunet_server_lib.h"
36 #include "gnunet-service-dns-p.h"
37 #include "gnunet_client_lib.h"
38 #include "gnunet_container_lib.h"
39
40 /**
41  * Final status code.
42  */
43 static int ret;
44
45 struct vpn_cls {
46         struct GNUNET_DISK_PipeHandle* helper_in; // From the helper
47         struct GNUNET_DISK_PipeHandle* helper_out; // To the helper
48         const struct GNUNET_DISK_FileHandle* fh_from_helper;
49         const struct GNUNET_DISK_FileHandle* fh_to_helper;
50
51         struct GNUNET_SERVER_MessageStreamTokenizer* mst;
52
53         struct GNUNET_SCHEDULER_Handle *sched;
54
55         struct GNUNET_CLIENT_Connection *dns_connection;
56
57         pid_t helper_pid;
58
59         struct query_packet_list *head;
60         struct query_packet_list *tail;
61
62         struct answer_packet_list *answer_head;
63         struct answer_packet_list *answer_tail;
64 };
65
66 static struct vpn_cls mycls;
67
68 static void cleanup(void* cls, const struct GNUNET_SCHEDULER_TaskContext* tskctx) {
69         if (tskctx->reason & GNUNET_SCHEDULER_REASON_SHUTDOWN) {
70                 PLIBC_KILL(mycls.helper_pid, SIGTERM);
71                 GNUNET_OS_process_wait(mycls.helper_pid);
72         }
73 }
74
75 static void helper_read(void* cls, const struct GNUNET_SCHEDULER_TaskContext* tsdkctx);
76
77 static void start_helper_and_schedule() {
78         mycls.helper_in = GNUNET_DISK_pipe (GNUNET_YES, GNUNET_YES, GNUNET_NO);;
79         mycls.helper_out = GNUNET_DISK_pipe (GNUNET_YES, GNUNET_NO, GNUNET_YES);
80
81         if (mycls.helper_in == NULL || mycls.helper_out == NULL) return;
82
83         mycls.helper_pid = GNUNET_OS_start_process(mycls.helper_in, mycls.helper_out, "gnunet-helper-vpn", "gnunet-helper-vpn", NULL);
84
85         mycls.fh_from_helper = GNUNET_DISK_pipe_handle (mycls.helper_out, GNUNET_DISK_PIPE_END_READ);
86         mycls.fh_to_helper = GNUNET_DISK_pipe_handle (mycls.helper_in, GNUNET_DISK_PIPE_END_WRITE);
87
88         GNUNET_DISK_pipe_close_end(mycls.helper_out, GNUNET_DISK_PIPE_END_WRITE);
89         GNUNET_DISK_pipe_close_end(mycls.helper_in, GNUNET_DISK_PIPE_END_READ);
90
91         GNUNET_SCHEDULER_add_read_file (mycls.sched, GNUNET_TIME_UNIT_FOREVER_REL, mycls.fh_from_helper, &helper_read, NULL);
92 }
93
94
95 static void restart_helper(void* cls, const struct GNUNET_SCHEDULER_TaskContext* tskctx) {
96         // FIXME: Ratelimit this!
97
98         // Kill the helper
99         PLIBC_KILL(mycls.helper_pid, SIGKILL);
100         GNUNET_OS_process_wait(mycls.helper_pid);
101
102         // FIXME: send msg to service-dns -- the hijacker has to be started again, too, the routing table is flushed if it depends on one interface
103
104         GNUNET_DISK_pipe_close(mycls.helper_in);
105         GNUNET_DISK_pipe_close(mycls.helper_out);
106
107         // Restart the helper
108         start_helper_and_schedule(mycls);
109
110 }
111
112 static void helper_read(void* cls, const struct GNUNET_SCHEDULER_TaskContext* tsdkctx) {
113         char buf[65535];
114
115         if (tsdkctx->reason & GNUNET_SCHEDULER_REASON_SHUTDOWN)
116                 return;
117
118         int t = GNUNET_DISK_file_read(mycls.fh_from_helper, &buf, 65535);
119         if (t<=0) {
120                 GNUNET_log(GNUNET_ERROR_TYPE_DEBUG, "Read error for header: %m\n");
121                 GNUNET_SCHEDULER_add_now(mycls.sched, restart_helper, cls);
122                 return;
123         }
124
125         /* FIXME */ GNUNET_SERVER_mst_receive(mycls.mst, NULL, buf, t, 0, 0);
126
127         GNUNET_SCHEDULER_add_read_file (mycls.sched, GNUNET_TIME_UNIT_FOREVER_REL, mycls.fh_from_helper, &helper_read, NULL);
128 }
129
130 static void helper_write(void* cls, const struct GNUNET_SCHEDULER_TaskContext* tsdkctx) {
131         if (tsdkctx->reason & GNUNET_SCHEDULER_REASON_SHUTDOWN)
132                 return;
133 }
134
135 size_t send_query(void* cls, size_t size, void* buf)
136 {
137         struct query_packet_list* query = mycls.head;
138         size_t len = ntohs(query->pkt.hdr.size);
139
140         GNUNET_assert(len <= size);
141
142         memcpy(buf, &query->pkt.hdr, len);
143
144         GNUNET_log(GNUNET_ERROR_TYPE_DEBUG, "Sent %d bytes.\n", len);
145
146         GNUNET_CONTAINER_DLL_remove (mycls.head, mycls.tail, query);
147
148         GNUNET_free(query);
149
150         if (mycls.head != NULL) {
151                 GNUNET_CLIENT_notify_transmit_ready(mycls.dns_connection, ntohs(mycls.head->pkt.hdr.size), GNUNET_TIME_UNIT_FOREVER_REL, GNUNET_YES, &send_query, NULL);
152         }
153
154         return len;
155 }
156
157 static void message_token(void *cls, void *client, const struct GNUNET_MessageHeader *message) {
158         if (ntohs(message->type) != GNUNET_MESSAGE_TYPE_VPN_HELPER) return;
159
160         struct tun_pkt *pkt_tun = (struct tun_pkt*) message;
161
162         if (ntohs(pkt_tun->tun.type) == 0x86dd) {
163                 struct ip6_pkt *pkt6 = (struct ip6_pkt*) message;
164                 struct ip6_tcp *pkt6_tcp;
165                 struct ip6_udp *pkt6_udp;
166
167                 pkt_printf(pkt6);
168                 switch(pkt6->ip6_hdr.nxthdr) {
169                         case 0x06:
170                                 pkt6_tcp = (struct ip6_tcp*)pkt6;
171                                 pkt_printf_ip6tcp(pkt6_tcp);
172                                 break;
173                         case 0x11:
174                                 pkt6_udp = (struct ip6_udp*)pkt6;
175                                 pkt_printf_ip6udp(pkt6_udp);
176                                 if (ntohs(pkt6_udp->udp_hdr.dpt) == 53) {
177                                         pkt_printf_ip6dns((struct ip6_udp_dns*)pkt6_udp);
178                                 }
179                                 break;
180                 }
181         } else if (ntohs(pkt_tun->tun.type) == 0x0800) {
182                 struct ip_pkt *pkt = (struct ip_pkt*) message;
183                 struct ip_udp *udp = (struct ip_udp*) message;
184                 if (pkt->ip_hdr.proto == 0x11 && ntohs(udp->udp_hdr.dpt) == 53 ) {
185                         size_t len = sizeof(struct query_packet) + ntohs(udp->udp_hdr.len) - 9; /* 9 = 8 for the udp-header + 1 for the unsigned char data[1]; */
186                         struct query_packet_list* query = GNUNET_malloc(len + 2*sizeof(struct query_packet_list*));
187                         query->pkt.hdr.type = htons(GNUNET_MESSAGE_TYPE_LOCAL_QUERY_DNS);
188                         query->pkt.hdr.size = htons(len);
189                         query->pkt.orig_to = pkt->ip_hdr.dadr;
190                         query->pkt.orig_from = pkt->ip_hdr.sadr;
191                         query->pkt.src_port = udp->udp_hdr.spt;
192                         memcpy(query->pkt.data, udp->data, ntohs(udp->udp_hdr.len) - 8);
193
194                         GNUNET_CONTAINER_DLL_insert_after(mycls.head, mycls.tail, mycls.tail, query);
195
196                         struct GNUNET_CLIENT_TransmitHandle* th = GNUNET_CLIENT_notify_transmit_ready(mycls.dns_connection, len, GNUNET_TIME_UNIT_FOREVER_REL, GNUNET_YES, &send_query, NULL);
197                         if (th != NULL)
198                                 GNUNET_log(GNUNET_ERROR_TYPE_DEBUG, "Queued sending of %d bytes.\n", len);
199                         else
200                                 GNUNET_log(GNUNET_ERROR_TYPE_DEBUG, "Already queued for %d bytes.\n", len);
201                 }
202         }
203
204 }
205
206 void dns_answer_handler(void* cls, const struct GNUNET_MessageHeader *msg) {
207         if (msg == NULL) return;
208         GNUNET_log(GNUNET_ERROR_TYPE_DEBUG, "Got an answer!\n");
209
210         if (msg->type != htons(GNUNET_MESSAGE_TYPE_LOCAL_RESPONSE_DNS)) goto out;
211
212         struct answer_packet_list* pkt = GNUNET_malloc(ntohs(msg->size) + 2*sizeof(struct answer_packet_list*));
213
214         memcpy(&pkt->pkt, msg, ntohs(msg->size));
215
216         GNUNET_CONTAINER_DLL_insert_after(mycls.answer_head, mycls.answer_tail, mycls.answer_tail, pkt);
217
218         GNUNET_SCHEDULER_add_write_file (mycls.sched, GNUNET_TIME_UNIT_FOREVER_REL, mycls.fh_to_helper, &helper_write, NULL);
219
220 out:
221         GNUNET_CLIENT_receive(mycls.dns_connection, &dns_answer_handler, NULL, GNUNET_TIME_UNIT_FOREVER_REL);
222 }
223
224 /**
225  * Main function that will be run by the scheduler.
226  *
227  * @param cls closure
228  * @param sched the scheduler to use
229  * @param args remaining command-line arguments
230  * @param cfgfile name of the configuration file used (for saving, can be NULL!)
231  * @param cfg configuration
232  */
233 static void
234 run (void *cls,
235      struct GNUNET_SCHEDULER_Handle *sched,
236      char *const *args,
237      const char *cfgfile,
238      const struct GNUNET_CONFIGURATION_Handle *cfg) 
239 {
240   mycls.sched = sched;
241   mycls.mst = GNUNET_SERVER_mst_create(&message_token, NULL);
242
243   mycls.dns_connection = GNUNET_CLIENT_connect (sched, "dns", cfg);
244   GNUNET_log(GNUNET_ERROR_TYPE_DEBUG, "Connection: %x\n", mycls.dns_connection);
245
246   GNUNET_CLIENT_receive(mycls.dns_connection, &dns_answer_handler, NULL, GNUNET_TIME_UNIT_FOREVER_REL);
247
248   GNUNET_SCHEDULER_add_delayed(sched, GNUNET_TIME_UNIT_FOREVER_REL, &cleanup, cls); 
249   start_helper_and_schedule(mycls);
250 }
251
252
253 /**
254  * The main function to obtain template from gnunetd.
255  *
256  * @param argc number of arguments from the command line
257  * @param argv command line arguments
258  * @return 0 ok, 1 on error
259  */
260 int
261 main (int argc, char *const *argv)
262 {
263   static const struct GNUNET_GETOPT_CommandLineOption options[] = {
264     GNUNET_GETOPT_OPTION_END
265   };
266
267   return (GNUNET_OK ==
268           GNUNET_PROGRAM_run (argc,
269                               argv,
270                               "gnunet-daemon-vpn",
271                               gettext_noop ("help text"),
272                               options, &run, NULL)) ? ret : 1;
273 }
274
275 /* end of gnunet-daemon-vpn.c */