2 This file is part of GNUnet.
3 Copyright (C) 2012, 2016 Christian Grothoff
5 GNUnet is free software: you can redistribute it and/or modify it
6 under the terms of the GNU Affero General Public License as published
7 by the Free Software Foundation, either version 3 of the License,
8 or (at your option) any later version.
10 GNUnet is distributed in the hope that it will be useful, but
11 WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 Affero General Public License for more details.
15 You should have received a copy of the GNU Affero General Public License
16 along with this program. If not, see <http://www.gnu.org/licenses/>.
18 SPDX-License-Identifier: AGPL3.0-or-later
23 * @brief library to access the VPN service and tell it how to redirect traffic
24 * @author Christian Grothoff
27 #include "gnunet_vpn_service.h"
34 struct GNUNET_VPN_Handle
37 * Configuration we use.
39 const struct GNUNET_CONFIGURATION_Handle *cfg;
42 * Connection to VPN service.
44 struct GNUNET_MQ_Handle *mq;
47 * Head of list of active redirection requests.
49 struct GNUNET_VPN_RedirectionRequest *rr_head;
52 * Tail of list of active redirection requests.
54 struct GNUNET_VPN_RedirectionRequest *rr_tail;
57 * Identifier of a reconnect task.
59 struct GNUNET_SCHEDULER_Task *rt;
62 * How long do we wait until we try to reconnect?
64 struct GNUNET_TIME_Relative backoff;
67 * ID of the last request that was submitted to the service.
69 uint64_t request_id_gen;
74 * Opaque redirection request handle.
76 struct GNUNET_VPN_RedirectionRequest
81 struct GNUNET_VPN_RedirectionRequest *next;
86 struct GNUNET_VPN_RedirectionRequest *prev;
89 * Pointer to the VPN struct.
91 struct GNUNET_VPN_Handle *vh;
94 * Target IP address for the redirection, or NULL for
95 * redirection to service. Allocated after this struct.
100 * Function to call with the designated IP address.
102 GNUNET_VPN_AllocationCallback cb;
110 * For service redirection, identity of the peer offering the service.
112 struct GNUNET_PeerIdentity peer;
115 * For service redirection, service descriptor.
117 struct GNUNET_HashCode serv;
120 * At what time should the created service mapping expire?
122 struct GNUNET_TIME_Absolute expiration_time;
125 * non-zero if this request has been sent to the service.
130 * Desired address family for the result.
135 * Address family of @e addr. AF_INET or AF_INET6.
140 * For service redirection, IPPROT_UDP or IPPROTO_TCP.
147 * Disconnect from the service (communication error) and reconnect later.
149 * @param vh handle to reconnect.
152 reconnect (struct GNUNET_VPN_Handle *vh);
156 * Check a #GNUNET_MESSAGE_TYPE_VPN_CLIENT_USE_IP message from the
159 * @param cls the `struct GNUNET_VPN_Handle`
160 * @param rm message received
161 * @return #GNUNET_OK if @a rm is well-formed
164 check_use_ip (void *cls,
165 const struct RedirectToIpResponseMessage *rm)
170 af = (int) ntohl (rm->result_af);
178 alen = sizeof(struct in_addr);
182 alen = sizeof(struct in6_addr);
187 return GNUNET_SYSERR;
189 if ((ntohs (rm->header.size) != alen + sizeof(*rm)) ||
190 (0 == rm->request_id))
193 return GNUNET_SYSERR;
200 * Handle a #GNUNET_MESSAGE_TYPE_VPN_CLIENT_USE_IP message from the
203 * @param cls the `struct GNUNET_VPN_Handle`
204 * @param rm message received
207 handle_use_ip (void *cls,
208 const struct RedirectToIpResponseMessage *rm)
210 struct GNUNET_VPN_Handle *vh = cls;
211 struct GNUNET_VPN_RedirectionRequest *rr;
214 af = (int) ntohl (rm->result_af);
215 for (rr = vh->rr_head; NULL != rr; rr = rr->next)
217 if (rr->request_id == rm->request_id)
219 GNUNET_CONTAINER_DLL_remove (vh->rr_head,
224 (af == AF_UNSPEC) ? NULL : &rm[1]);
233 * Add a request to our request queue and transmit it.
235 * @param rr request to queue and transmit.
238 send_request (struct GNUNET_VPN_RedirectionRequest *rr)
240 struct GNUNET_VPN_Handle *vh = rr->vh;
241 struct RedirectToIpRequestMessage *rip;
242 struct RedirectToServiceRequestMessage *rs;
243 struct GNUNET_MQ_Envelope *env;
248 if (NULL == rr->addr)
250 env = GNUNET_MQ_msg (rs,
251 GNUNET_MESSAGE_TYPE_VPN_CLIENT_REDIRECT_TO_SERVICE);
252 rs->reserved = htonl (0);
253 rs->expiration_time = GNUNET_TIME_absolute_hton (rr->expiration_time);
254 rs->protocol = htonl (rr->protocol);
255 rs->result_af = htonl (rr->result_af);
256 rs->target = rr->peer;
257 rs->service_descriptor = rr->serv;
258 rs->request_id = rr->request_id = ++vh->request_id_gen;
265 alen = sizeof(struct in_addr);
269 alen = sizeof(struct in6_addr);
276 env = GNUNET_MQ_msg_extra (rip,
278 GNUNET_MESSAGE_TYPE_VPN_CLIENT_REDIRECT_TO_IP);
279 rip->reserved = htonl (0);
280 rip->expiration_time = GNUNET_TIME_absolute_hton (rr->expiration_time);
281 rip->result_af = htonl (rr->result_af);
282 rip->addr_af = htonl (rr->addr_af);
283 rip->request_id = rr->request_id = ++vh->request_id_gen;
284 GNUNET_memcpy (&rip[1],
288 GNUNET_MQ_send (vh->mq,
294 * Generic error handler, called with the appropriate error code and
295 * the same closure specified at the creation of the message queue.
296 * Not every message queue implementation supports an error handler.
298 * @param cls closure with the `struct GNUNET_VPN_Handle *`
299 * @param error error code
302 mq_error_handler (void *cls,
303 enum GNUNET_MQ_Error error)
305 struct GNUNET_VPN_Handle *vh = cls;
312 * Connect to the VPN service and start again to transmit our requests.
314 * @param cls the `struct GNUNET_VPN_Handle *`
317 connect_task (void *cls)
319 struct GNUNET_VPN_Handle *vh = cls;
320 struct GNUNET_MQ_MessageHandler handlers[] = {
321 GNUNET_MQ_hd_var_size (use_ip,
322 GNUNET_MESSAGE_TYPE_VPN_CLIENT_USE_IP,
323 struct RedirectToIpResponseMessage,
325 GNUNET_MQ_handler_end ()
327 struct GNUNET_VPN_RedirectionRequest *rr;
330 vh->mq = GNUNET_CLIENT_connect (vh->cfg,
337 for (rr = vh->rr_head; NULL != rr; rr = rr->next)
343 * Disconnect from the service (communication error) and reconnect later.
345 * @param vh handle to reconnect.
348 reconnect (struct GNUNET_VPN_Handle *vh)
350 struct GNUNET_VPN_RedirectionRequest *rr;
352 GNUNET_MQ_destroy (vh->mq);
354 vh->request_id_gen = 0;
355 for (rr = vh->rr_head; NULL != rr; rr = rr->next)
357 vh->backoff = GNUNET_TIME_relative_max (GNUNET_TIME_UNIT_MILLISECONDS,
358 GNUNET_TIME_relative_min (
359 GNUNET_TIME_relative_saturating_multiply (
361 GNUNET_TIME_relative_multiply (
362 GNUNET_TIME_UNIT_SECONDS, 30)));
363 vh->rt = GNUNET_SCHEDULER_add_delayed (vh->backoff,
370 * Cancel redirection request with the service.
372 * @param rr request to cancel
375 GNUNET_VPN_cancel_request (struct GNUNET_VPN_RedirectionRequest *rr)
377 struct GNUNET_VPN_Handle *vh;
380 GNUNET_CONTAINER_DLL_remove (vh->rr_head,
388 * Tell the VPN that a forwarding to a particular peer offering a
389 * particular service is requested. The VPN is to reserve a
390 * particular IP for the redirection and return it. The VPN will
391 * begin the redirection as soon as possible and maintain it as long
392 * as it is actively used and keeping it is feasible. Given resource
393 * limitations, the longest inactive mappings will be destroyed.
395 * @param vh VPN handle
396 * @param result_af desired address family for the returned allocation
397 * can also be AF_UNSPEC
398 * @param protocol protocol, IPPROTO_UDP or IPPROTO_TCP
399 * @param peer target peer for the redirection
400 * @param serv service descriptor to give to the peer
401 * @param expiration_time at what time should the redirection expire?
402 * (this should not impact connections that are active at that time)
403 * @param cb function to call with the IP
404 * @param cb_cls closure for @a cb
405 * @return handle to cancel the request (means the callback won't be
406 * invoked anymore; the mapping may or may not be established
409 struct GNUNET_VPN_RedirectionRequest *
410 GNUNET_VPN_redirect_to_peer (struct GNUNET_VPN_Handle *vh,
413 const struct GNUNET_PeerIdentity *peer,
414 const struct GNUNET_HashCode *serv,
415 struct GNUNET_TIME_Absolute expiration_time,
416 GNUNET_VPN_AllocationCallback cb,
419 struct GNUNET_VPN_RedirectionRequest *rr;
421 rr = GNUNET_new (struct GNUNET_VPN_RedirectionRequest);
427 rr->expiration_time = expiration_time;
428 rr->result_af = result_af;
429 rr->protocol = protocol;
430 GNUNET_CONTAINER_DLL_insert_tail (vh->rr_head,
439 * Tell the VPN that forwarding to the Internet via some exit node is
440 * requested. Note that both UDP and TCP traffic will be forwarded,
441 * but possibly to different exit nodes. The VPN is to reserve a
442 * particular IP for the redirection and return it. The VPN will
443 * begin the redirection as soon as possible and maintain it as long
444 * as it is actively used and keeping it is feasible. Given resource
445 * limitations, the longest inactive mappings will be destroyed.
447 * @param vh VPN handle
448 * @param result_af desired address family for the returned allocation
449 * @param addr_af address family for @a addr, AF_INET or AF_INET6
450 * @param addr destination IP address on the Internet; destination
451 * port is to be taken from the VPN packet itself
452 * @param expiration_time at what time should the redirection expire?
453 * (this should not impact connections that are active at that time)
454 * @param cb function to call with the IP
455 * @param cb_cls closure for @a cb
456 * @return handle to cancel the request (means the callback won't be
457 * invoked anymore; the mapping may or may not be established
460 struct GNUNET_VPN_RedirectionRequest *
461 GNUNET_VPN_redirect_to_ip (struct GNUNET_VPN_Handle *vh,
465 struct GNUNET_TIME_Absolute expiration_time,
466 GNUNET_VPN_AllocationCallback cb,
469 struct GNUNET_VPN_RedirectionRequest *rr;
475 alen = sizeof(struct in_addr);
479 alen = sizeof(struct in6_addr);
486 rr = GNUNET_malloc (sizeof(struct GNUNET_VPN_RedirectionRequest) + alen);
491 rr->expiration_time = expiration_time;
492 rr->result_af = result_af;
493 rr->addr_af = addr_af;
494 GNUNET_memcpy (&rr[1],
497 GNUNET_CONTAINER_DLL_insert_tail (vh->rr_head,
506 * Connect to the VPN service
508 * @param cfg configuration to use
511 struct GNUNET_VPN_Handle *
512 GNUNET_VPN_connect (const struct GNUNET_CONFIGURATION_Handle *cfg)
514 struct GNUNET_VPN_Handle *vh
515 = GNUNET_new (struct GNUNET_VPN_Handle);
529 * Disconnect from the VPN service.
531 * @param vh VPN handle
534 GNUNET_VPN_disconnect (struct GNUNET_VPN_Handle *vh)
536 GNUNET_assert (NULL == vh->rr_head);
539 GNUNET_MQ_destroy (vh->mq);
544 GNUNET_SCHEDULER_cancel (vh->rt);
551 /* end of vpn_api.c */