X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ian/git?p=hippotat.git;a=blobdiff_plain;f=server;h=3abebe96bfb69bdf5921dfa64cf1a8da2f70bbf0;hp=9d8338616e76c6343a6947e890f870d222eb2e55;hb=8e279651cf76bb0e7d532307c0afbfbd7dc4986b;hpb=e75e9c176dde9a52258bc43631c8a4a2973d59fe diff --git a/server b/server index 9d83386..3abebe9 100755 --- a/server +++ b/server @@ -1,14 +1,27 @@ #!/usr/bin/python3 -import twisted.web.server import Site -from twisted.web.resource import Resource -from twisted.web.server import NOT_DONE_YET +import signal +signal.signal(signal.SIGINT, signal.SIG_DFL) + +import sys +import os + +import twisted +import twisted.internet +import twisted.internet.endpoints from twisted.internet import reactor +from twisted.web.server import NOT_DONE_YET +from twisted.logger import LogLevel + +import ipaddress +from ipaddress import AddressValueError + +#import twisted.web.server import Site +#from twisted.web.resource import Resource from optparse import OptionParser from configparser import ConfigParser from configparser import NoOptionError -import ipaddress import collections @@ -16,7 +29,7 @@ import syslog clients = { } -def ipaddress(input): +def ipaddr(input): try: r = ipaddress.IPv4Address(input) except AddressValueError: @@ -43,7 +56,9 @@ mtu = 1500 # [relay] [server] -ipif_program = userv root ipif %(host),%(relay),%(mtu),slip %(network) +ipif = userv root ipif %(host)s,%(relay)s,%(mtu)s,slip %(network)s +addrs = 127.0.0.1 ::1 +port = 8099 [limits] max_batch_down = 262144 @@ -51,15 +66,127 @@ max_queue_time = 121 max_request_time = 121 ''' -def route(packet. daddr): +#---------- error handling ---------- + +def crash(err): + print('CRASH ', err, file=sys.stderr) + try: reactor.stop() + except twisted.internet.error.ReactorNotRunning: pass + +def crash_on_defer(defer): + defer.addErrback(lambda err: crash(err)) + +def crash_on_critical(event): + if event.get('log_level') >= LogLevel.critical: + crash(twisted.logger.formatEvent(event)) + +#---------- "router" ---------- + +def route(packet, saddr, daddr): + print('TRACE ', saddr, daddr, packet) try: client = clients[daddr] except KeyError: dclient = None if dclient is not None: dclient.queue_outbound(packet) - else if daddr = server or daddr not in network: + elif saddr.is_link_local or daddr.is_link_local: + log_discard(packet, saddr, daddr, 'link-local') + elif daddr == host or daddr not in network: + print('TRACE INBOUND ', saddr, daddr, packet) queue_inbound(packet) + elif daddr == relay: + log_discard(packet, saddr, daddr, 'relay') + else: + log_discard(packet, saddr, daddr, 'no client') + +def log_discard(packet, saddr, daddr, why): + print('DROP ', saddr, daddr, why) +# syslog.syslog(syslog.LOG_DEBUG, +# 'discarded packet %s -> %s (%s)' % (saddr, daddr, why)) + +#---------- ipif (slip subprocess) ---------- + +class IpifProcessProtocol(twisted.internet.protocol.ProcessProtocol): + def __init__(self): + self._buffer = b'' + def connectionMade(self): pass + def outReceived(self, data): + #print('RECV ', repr(data)) + self._buffer += data + packets = slip_decode(self._buffer) + self._buffer = packets.pop() + for packet in packets: + if not len(packet): continue + (saddr, daddr) = packet_addrs(packet) + route(packet, saddr, daddr) + def processEnded(self, status): + status.raiseException() + +def start_ipif(): + global ipif + ipif = IpifProcessProtocol() + reactor.spawnProcess(ipif, + '/bin/sh',['sh','-xc', ipif_command], + childFDs={0:'w', 1:'r', 2:2}) + +def queue_inbound(packet): + ipif.transport.write(slip_delimiter) + ipif.transport.write(slip_encode(packet)) + ipif.transport.write(slip_delimiter) + +#---------- SLIP handling ---------- + +slip_end = b'\300' +slip_esc = b'\333' +slip_esc_end = b'\334' +slip_esc_esc = b'\335' +slip_delimiter = slip_end + +def slip_encode(packet): + return (packet + .replace(slip_esc, slip_esc + slip_esc_esc) + .replace(slip_end, slip_esc + slip_esc_end)) + +def slip_decode(data): + print('DECODE ', repr(data)) + out = [] + for packet in data.split(slip_end): + pdata = b'' + while True: + eix = packet.find(slip_esc) + if eix == -1: + pdata += packet + break + #print('ESC ', repr((pdata, packet, eix))) + pdata += packet[0 : eix] + ck = packet[eix+1] + #print('ESC... %o' % ck) + if ck == slip_esc_esc[0]: pdata += slip_esc + elif ck == slip_esc_end[0]: pdata += slip_end + else: raise ValueError('invalid SLIP escape') + packet = packet[eix+2 : ] + out.append(pdata) + print('DECODED ', repr(out)) + return out + +#---------- packet parsing ---------- + +def packet_addrs(packet): + version = packet[0] >> 4 + if version == 4: + addrlen = 4 + saddroff = 3*4 + factory = ipaddress.IPv4Address + elif version == 6: + addrlen = 16 + saddroff = 2*4 + factory = ipaddress.IPv6Address else: - syslog.syslog(syslog.LOG_DEBUG, 'no client for %s' % daddr) + raise ValueError('unsupported IP version %d' % version) + saddr = factory(packet[ saddroff : saddroff + addrlen ]) + daddr = factory(packet[ saddroff + addrlen : saddroff + addrlen*2 ]) + return (saddr, daddr) + +#---------- client ---------- class Client(): def __init__(self, ip, cs): @@ -80,10 +207,10 @@ class Client(): def process_arriving_data(self, d): for packet in slip_decode(d): - (saddr, daddr) = ip_64_addrs(packet) + (saddr, daddr) = packet_addrs(packet) if saddr != self._ip: raise ValueError('wrong source address %s' % saddr) - route(packet, daddr) + route(packet, saddr, daddr) def _req_cancel(self, request): request.finish() @@ -111,7 +238,7 @@ class Client(): # now request is an unfinished request, or None try: (queuetime, packet) = self._pq[0] - except: IndexError: + except IndexError: # no packets, oh well break @@ -145,10 +272,52 @@ class Client(): request.finish() # round again, looking for more to do +class IphttpResource(twisted.web.resource.Resource): + def render_POST(self, request): + # find client, update config, etc. + ci = ipaddr(request.args['i']) + c = clients[ci] + pw = request.args['pw'] + if pw != c.pw: raise ValueError('bad password') + + # update config + for r, w in (('mbd', 'max_batch_down'), + ('mqt', 'max_queue_time'), + ('mrt', 'max_request_time')): + try: v = request.args[r] + except KeyError: continue + v = int(v) + c.__dict__[w] = v + + try: d = request.args['d'] + except KeyError: d = '' + + c.process_arriving_data(d) + c.new_request(request) + + def render_GET(self, request): + return 'hippotit' + +def start_http(): + resource = IphttpResource() + sitefactory = twisted.web.server.Site(resource) + for addrspec in cfg.get('server','addrs').split(): + try: + addr = ipaddress.IPv4Address(addrspec) + endpointfactory = twisted.internet.endpoints.TCP4ServerEndpoint + except AddressValueError: + addr = ipaddress.IPv6Address(addrspec) + endpointfactory = twisted.internet.endpoints.TCP6ServerEndpoint + ep = endpointfactory(reactor, cfg.getint('server','port'), addr) + crash_on_defer(ep.listen(sitefactory)) + +#---------- config and setup ---------- + def process_cfg(): global network global host global relay + global ipif_command network = ipnetwork(cfg.get('virtual','network')) if network.num_addresses < 3 + 2: @@ -157,49 +326,37 @@ def process_cfg(): try: host = cfg.get('virtual','host') except NoOptionError: - host = network.hosts().next() + host = next(network.hosts()) try: relay = cfg.get('virtual','relay') - except OptionError: + except NoOptionError: for search in network.hosts(): - if search = host: continue + if search == host: continue relay = search break for cs in cfg.sections(): if not (':' in cs or '.' in cs): continue - ci = ipaddress(cs) + ci = ipaddr(cs) if ci not in network: raise ValueError('client %s not in network' % ci) if ci in clients: raise ValueError('multiple client cfg sections for %s' % ci) clients[ci] = Client(ci, cs) -class FormPage(Resource): - def render_POST(self, request): - # find client, update config, etc. - ci = ipaddress(request.args['i']) - c = clients[ci] - pw = request.args['pw'] - if pw != c.pw: raise ValueError('bad password') + global mtu + mtu = cfg.get('virtual','mtu') - # update config - for r, w in (('mbd', 'max_batch_down'), - ('mqt', 'max_queue_time'), - ('mrt', 'max_request_time')): - try: v = request.args[r] - except KeyError: continue - v = int(v) - c.__dict__[w] = v - - try: d = request.args['d'] - except KeyError: d = '' + iic_vars = { } + for k in ('host','relay','mtu','network'): + iic_vars[k] = globals()[k] - c.process_arriving_data(d) - c.new_request(request) + ipif_command = cfg.get('server','ipif', vars=iic_vars) def startup(): + global cfg + op = OptionParser() op.add_option('-c', '--config', dest='configfile', default='/etc/hippottd/server.conf') @@ -207,5 +364,16 @@ def startup(): (opts, args) = op.parse_args() if len(args): op.error('no non-option arguments please') + twisted.logger.globalLogPublisher.addObserver(crash_on_critical) + cfg = ConfigParser() - + cfg.read_string(defcfg) + cfg.read(opts.configfile) + process_cfg() + + start_ipif() + start_http() + +startup() +reactor.run() +print('CRASHED (end)', file=sys.stderr)