* IP traffic received on those IPs via the GNUnet mesh
* @author Philipp Toelke
* @author Christian Grothoff
+ *
+ * TODO:
+ * - keep multiple peers/mesh tunnels ready as alternative exits /
+ * recover from tunnel-to-exit failure gracefully
*/
#include "platform.h"
#include "gnunet_util_lib.h"
#include "gnunet_statistics_service.h"
#include "gnunet_constants.h"
#include "gnunet_tun_lib.h"
-#include "gnunet_regex_lib.h"
+#include "gnunet_regex_service.h"
#include "vpn.h"
#include "exit.h"
#define MAX_MESSAGE_QUEUE_SIZE 4
+#define PORT_VPN 42
+
/**
* State we keep for each of our tunnels.
*/
*/
struct GNUNET_MESH_Tunnel *tunnel;
+ /**
+ * Active query with REGEX to locate exit.
+ */
+ struct GNUNET_REGEX_Search *search;
+
/**
* Active transmission handle, NULL for none.
*/
GNUNET_free (tnq);
}
GNUNET_assert (0 == ts->tmq_length);
- if (NULL != ts->client)
- {
- GNUNET_SERVER_client_drop (ts->client);
- ts->client = NULL;
- }
if (NULL != ts->th)
{
GNUNET_MESH_notify_transmit_ready_cancel (ts->th);
ts->tunnel = NULL;
GNUNET_MESH_tunnel_destroy (tunnel);
}
+ if (NULL != ts->search)
+ {
+ GNUNET_REGEX_search_cancel (ts->search);
+ ts->search = NULL;
+ }
if (GNUNET_SCHEDULER_NO_TASK != ts->destroy_task)
{
GNUNET_SCHEDULER_cancel (ts->destroy_task);
/**
* Method called whenever a peer has disconnected from the tunnel.
*
+ * FIXME merge with inbound_cleaner
+ *
* @param cls closure
* @param peer peer identity the tunnel stopped working with
*/
-static void
+void
tunnel_peer_disconnect_handler (void *cls,
const struct
GNUNET_PeerIdentity * peer)
* Method called whenever a peer has connected to the tunnel. Notifies
* the waiting client that the tunnel is now up.
*
+ * FIXME merge with tunnel_create
+ *
* @param cls closure
* @param peer peer identity the tunnel was created to, NULL on timeout
* @param atsi performance data for the connection
*/
-static void
+void
tunnel_peer_connect_handler (void *cls,
const struct GNUNET_PeerIdentity
* peer,
ts->request_id,
ts->af,
&ts->destination_ip);
- GNUNET_SERVER_client_drop (ts->client);
ts->client = NULL;
}
ts->th = GNUNET_MESH_notify_transmit_ready (ts->tunnel,
GNUNET_NO /* cork */,
GNUNET_TIME_UNIT_FOREVER_REL,
- NULL,
tnq->len,
&send_to_peer_notify_callback,
ts);
ts->th = GNUNET_MESH_notify_transmit_ready (ts->tunnel,
GNUNET_NO /* cork */,
GNUNET_TIME_UNIT_FOREVER_REL,
- NULL,
tnq->len,
&send_to_peer_notify_callback,
ts);
}
+/**
+ * Regex has found a potential exit peer for us; consider using it.
+ *
+ * @param cls the 'struct TunnelState'
+ * @param id Peer providing a regex that matches the string.
+ * @param get_path Path of the get request.
+ * @param get_path_length Lenght of get_path.
+ * @param put_path Path of the put request.
+ * @param put_path_length Length of the put_path.
+ */
+static void
+handle_regex_result (void *cls,
+ const struct GNUNET_PeerIdentity *id,
+ const struct GNUNET_PeerIdentity *get_path,
+ unsigned int get_path_length,
+ const struct GNUNET_PeerIdentity *put_path,
+ unsigned int put_path_length)
+{
+ struct TunnelState *ts = cls;
+
+ GNUNET_REGEX_search_cancel (ts->search);
+ ts->search = NULL;
+ ts->tunnel = GNUNET_MESH_tunnel_create (mesh_handle,
+ ts,
+ id,
+ PORT_VPN,
+ GNUNET_YES,
+ GNUNET_NO);
+}
+
+
/**
* Initialize the given destination entry's mesh tunnel.
*
{
ts->request_id = request_id;
ts->client = client;
- GNUNET_SERVER_client_keep (client);
}
ts->destination = *de;
ts->destination.heap_node = NULL; /* copy is NOT in destination heap */
de->ts = ts;
ts->destination_container = de; /* we are referenced from de */
- ts->tunnel = GNUNET_MESH_tunnel_create (mesh_handle,
- ts,
- &tunnel_peer_connect_handler,
- &tunnel_peer_disconnect_handler,
- ts);
- if (NULL == ts->tunnel)
- {
- GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
- _("Failed to setup mesh tunnel!\n"));
- if (NULL != client)
- GNUNET_SERVER_client_drop (client);
- GNUNET_free (ts);
- return NULL;
- }
if (de->is_service)
{
+ ts->tunnel = GNUNET_MESH_tunnel_create (mesh_handle,
+ ts,
+ &de->details.service_destination.target,
+ PORT_VPN,
+ GNUNET_YES,
+ GNUNET_NO);
+ if (NULL == ts->tunnel)
+ {
+ GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
+ _("Failed to setup mesh tunnel!\n"));
+ GNUNET_free (ts);
+ return NULL;
+ }
GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
"Creating tunnel to peer %s offering service %s\n",
GNUNET_i2s (&de->details.service_destination.target),
GNUNET_h2s (&de->details.service_destination.service_descriptor));
- GNUNET_MESH_peer_request_connect_add (ts->tunnel,
- &de->details.service_destination.target);
}
else
{
{
case AF_INET:
{
- char address[GNUNET_REGEX_IPV4_REGEXLEN];
- GNUNET_REGEX_ipv4toregex (&de->details.exit_destination.ip.v4,
- "255.255.255.255", address);
+ char address[GNUNET_TUN_IPV4_REGEXLEN];
+
+ GNUNET_TUN_ipv4toregexsearch (&de->details.exit_destination.ip.v4,
+ "255.255.255.255", address);
GNUNET_asprintf (&policy, "%s%s%s",
GNUNET_APPLICATION_TYPE_EXIT_REGEX_PREFIX,
"4",
}
case AF_INET6:
{
- char address[GNUNET_REGEX_IPV6_REGEXLEN];
- GNUNET_REGEX_ipv6toregex (&de->details.exit_destination.ip.v6,
- 128, address);
+ char address[GNUNET_TUN_IPV6_REGEXLEN];
+
+ GNUNET_TUN_ipv6toregexsearch (&de->details.exit_destination.ip.v6,
+ 128, address);
GNUNET_asprintf (&policy, "%s%s%s",
GNUNET_APPLICATION_TYPE_EXIT_REGEX_PREFIX,
"6",
break;
}
- GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Requesting connect by string: %s\n", policy);
-
- GNUNET_MESH_peer_request_connect_by_string (ts->tunnel, policy);
GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
- "Creating tunnel to exit peer for policy `%s'\n",
- policy);
+ "Requesting connect by string: %s\n",
+ policy);
+ ts->search = GNUNET_REGEX_search (cfg,
+ policy,
+ &handle_regex_result,
+ ts);
GNUNET_free (policy);
}
return ts;
ts->destination_port = destination_port;
ts->heap_node = GNUNET_CONTAINER_heap_insert (tunnel_heap,
ts,
- GNUNET_TIME_absolute_get ().abs_value);
+ GNUNET_TIME_absolute_get ().abs_value_us);
GNUNET_assert (GNUNET_YES ==
GNUNET_CONTAINER_multihashmap_put (tunnel_map,
&key,
is_new = GNUNET_NO;
GNUNET_CONTAINER_heap_update_cost (tunnel_heap,
ts->heap_node,
- GNUNET_TIME_absolute_get ().abs_value);
+ GNUNET_TIME_absolute_get ().abs_value_us);
}
GNUNET_assert (NULL != ts->tunnel);
* @param cls closure, NULL
* @param tunnel connection to the other end
* @param tunnel_ctx pointer to our 'struct TunnelState *'
- * @param sender who sent the message
* @param message the actual message
- * @param atsi performance data for the connection
+ *
* @return GNUNET_OK to keep the connection open,
* GNUNET_SYSERR to close it (signal serious error)
*/
static int
receive_icmp_back (void *cls GNUNET_UNUSED, struct GNUNET_MESH_Tunnel *tunnel,
- void **tunnel_ctx, const struct GNUNET_PeerIdentity *sender,
- const struct GNUNET_MessageHeader *message,
- const struct GNUNET_ATS_Information *atsi GNUNET_UNUSED)
+ void **tunnel_ctx,
+ const struct GNUNET_MessageHeader *message)
{
struct TunnelState *ts = *tunnel_ctx;
const struct GNUNET_EXIT_IcmpToVPNMessage *i2v;
}
GNUNET_CONTAINER_heap_update_cost (tunnel_heap,
ts->heap_node,
- GNUNET_TIME_absolute_get ().abs_value);
+ GNUNET_TIME_absolute_get ().abs_value_us);
return GNUNET_OK;
}
* @param cls closure, NULL
* @param tunnel connection to the other end
* @param tunnel_ctx pointer to our 'struct TunnelState *'
- * @param sender who sent the message
* @param message the actual message
- * @param atsi performance data for the connection
+ *
* @return GNUNET_OK to keep the connection open,
* GNUNET_SYSERR to close it (signal serious error)
*/
static int
receive_udp_back (void *cls GNUNET_UNUSED, struct GNUNET_MESH_Tunnel *tunnel,
- void **tunnel_ctx, const struct GNUNET_PeerIdentity *sender,
- const struct GNUNET_MessageHeader *message,
- const struct GNUNET_ATS_Information *atsi GNUNET_UNUSED)
+ void **tunnel_ctx,
+ const struct GNUNET_MessageHeader *message)
{
struct TunnelState *ts = *tunnel_ctx;
const struct GNUNET_EXIT_UdpReplyMessage *reply;
}
GNUNET_CONTAINER_heap_update_cost (tunnel_heap,
ts->heap_node,
- GNUNET_TIME_absolute_get ().abs_value);
+ GNUNET_TIME_absolute_get ().abs_value_us);
return GNUNET_OK;
}
* @param cls closure, NULL
* @param tunnel connection to the other end
* @param tunnel_ctx pointer to our 'struct TunnelState *'
- * @param sender who sent the message
* @param message the actual message
- * @param atsi performance data for the connection
+ *
* @return GNUNET_OK to keep the connection open,
* GNUNET_SYSERR to close it (signal serious error)
*/
static int
receive_tcp_back (void *cls GNUNET_UNUSED, struct GNUNET_MESH_Tunnel *tunnel,
void **tunnel_ctx,
- const struct GNUNET_PeerIdentity *sender GNUNET_UNUSED,
- const struct GNUNET_MessageHeader *message,
- const struct GNUNET_ATS_Information *atsi GNUNET_UNUSED)
+ const struct GNUNET_MessageHeader *message)
{
struct TunnelState *ts = *tunnel_ctx;
const struct GNUNET_EXIT_TcpDataMessage *data;
}
GNUNET_CONTAINER_heap_update_cost (tunnel_heap,
ts->heap_node,
- GNUNET_TIME_absolute_get ().abs_value);
+ GNUNET_TIME_absolute_get ().abs_value_us);
return GNUNET_OK;
}
GNUNET_CONTAINER_MULTIHASHMAPOPTION_MULTIPLE));
de->heap_node = GNUNET_CONTAINER_heap_insert (destination_heap,
de,
- GNUNET_TIME_absolute_ntoh (msg->expiration_time).abs_value);
+ GNUNET_TIME_absolute_ntoh (msg->expiration_time).abs_value_us);
GNUNET_STATISTICS_update (stats,
gettext_noop ("# Active destinations"),
1, GNUNET_NO);
GNUNET_CONTAINER_MULTIHASHMAPOPTION_MULTIPLE));
de->heap_node = GNUNET_CONTAINER_heap_insert (destination_heap,
de,
- GNUNET_TIME_absolute_ntoh (msg->expiration_time).abs_value);
+ GNUNET_TIME_absolute_ntoh (msg->expiration_time).abs_value_us);
while (GNUNET_CONTAINER_multihashmap_size (destination_map) > max_destination_mappings)
expire_destination (de);
ts = create_tunnel_to_destination (de,
}
-
-/**
- * Function called for inbound tunnels. As we don't offer
- * any mesh services, this function should never be called.
- *
- * @param cls closure
- * @param tunnel new handle to the tunnel
- * @param initiator peer that started the tunnel
- * @param atsi performance information for the tunnel
- * @return initial tunnel context for the tunnel
- * (can be NULL -- that's not an error)
- */
-static void *
-inbound_tunnel_cb (void *cls, struct GNUNET_MESH_Tunnel *tunnel,
- const struct GNUNET_PeerIdentity *initiator,
- const struct GNUNET_ATS_Information *atsi)
-{
- /* How can and why should anyone open an inbound tunnel to vpn? */
- GNUNET_break (0);
- return NULL;
-}
-
-
/**
* Function called whenever an inbound tunnel is destroyed. Should clean up
* any associated state.
+ *
+ * FIXME now its also user for disconnections
*
* @param cls closure (set from GNUNET_MESH_connect)
* @param tunnel connection to the other end (henceforth invalid)
mesh_handle = NULL;
}
if (NULL != helper_handle)
- {
- GNUNET_HELPER_stop (helper_handle);
+ {
+ GNUNET_HELPER_stop (helper_handle, GNUNET_NO);
helper_handle = NULL;
}
if (NULL != nc)
struct TunnelState *ts = value;
if (client == ts->client)
- {
- GNUNET_SERVER_client_drop (ts->client);
ts->client = NULL;
- }
return GNUNET_OK;
}
if (NULL == (ts = de->ts))
return GNUNET_OK;
if (client == ts->client)
- {
- GNUNET_SERVER_client_drop (ts->client);
ts->client = NULL;
- }
return GNUNET_OK;
}
{ &receive_icmp_back, GNUNET_MESSAGE_TYPE_VPN_ICMP_TO_VPN, 0},
{NULL, 0, 0}
};
- static const GNUNET_MESH_ApplicationType types[] = {
- GNUNET_APPLICATION_TYPE_END
- };
char *ifname;
char *ipv6addr;
char *ipv6prefix_s;
binary = GNUNET_OS_get_libexec_binary_path ("gnunet-helper-vpn");
if (GNUNET_YES !=
- GNUNET_OS_check_helper_binary (binary, TRUE, NULL)) // FIXME: CF: add test-parameters
+ GNUNET_OS_check_helper_binary (binary, GNUNET_YES, "-d gnunet-vpn - - 169.1.3.3.7 255.255.255.0")) //ipv4 only please!
{
fprintf (stderr,
"`%s' is not SUID, refusing to run.\n",
mesh_handle =
GNUNET_MESH_connect (cfg_, NULL,
- &inbound_tunnel_cb,
+ NULL,
&tunnel_cleaner,
mesh_handlers,
- types);
+ NULL);
helper_handle = GNUNET_HELPER_start (GNUNET_NO,
"gnunet-helper-vpn", vpn_argv,
&message_token, NULL, NULL);