10 #include <sys/utsname.h>
11 #include <sys/socket.h>
15 #ifdef HAVE_LINUX_IF_H
16 #include <linux/if_tun.h>
17 #define LINUX_TUN_SUPPORTED
21 #ifdef HAVE_NET_ROUTE_H
22 #include <net/route.h>
25 #if defined(HAVE_STROPTS_H) && defined(HAVE_SYS_SOCKIO_H) && \
26 defined(HAVE_NET_IF_TUN_H)
27 #define HAVE_TUN_STREAMS
30 #ifdef HAVE_TUN_STREAMS
32 #include <sys/sockio.h>
33 #include <net/if_tun.h>
36 #define TUN_FLAVOUR_GUESS 0
37 #define TUN_FLAVOUR_BSD 1
38 #define TUN_FLAVOUR_LINUX 2
39 #define TUN_FLAVOUR_STREAMS 3
41 static struct flagstr flavours[]={
42 {"guess", TUN_FLAVOUR_GUESS},
43 {"bsd", TUN_FLAVOUR_BSD},
44 {"BSD", TUN_FLAVOUR_BSD},
45 {"linux", TUN_FLAVOUR_LINUX},
46 {"streams", TUN_FLAVOUR_STREAMS},
47 {"STREAMS", TUN_FLAVOUR_STREAMS},
51 #define TUN_CONFIG_GUESS 0
52 #define TUN_CONFIG_IOCTL 1
53 #define TUN_CONFIG_BSD 2
54 #define TUN_CONFIG_LINUX 3
55 #define TUN_CONFIG_SOLARIS25 4
57 static struct flagstr config_types[]={
58 {"guess", TUN_CONFIG_GUESS},
59 {"ioctl", TUN_CONFIG_IOCTL},
60 {"bsd", TUN_CONFIG_BSD},
61 {"BSD", TUN_CONFIG_BSD},
62 {"linux", TUN_CONFIG_LINUX},
63 {"solaris-2.5", TUN_CONFIG_SOLARIS25},
67 /* Connection to the kernel through the universal TUN/TAP driver */
72 cstring_t device_path;
74 string_t interface_name;
75 cstring_t ifconfig_path;
76 uint32_t ifconfig_type;
80 bool_t search_for_if; /* Applies to tun-BSD only */
81 struct buffer_if *buff; /* We receive packets into here
82 and send them to the netlink code. */
83 netlink_deliver_fn *netlink_to_tunnel;
84 uint32_t local_address; /* host interface address */
87 static cstring_t tun_flavour_str(uint32_t flavour)
90 case TUN_FLAVOUR_GUESS: return "guess";
91 case TUN_FLAVOUR_BSD: return "BSD";
92 case TUN_FLAVOUR_LINUX: return "linux";
93 case TUN_FLAVOUR_STREAMS: return "STREAMS";
94 default: return "unknown";
98 static int tun_beforepoll(void *sst, struct pollfd *fds, int *nfds_io,
104 fds[0].events=POLLIN;
108 static void tun_afterpoll(void *sst, struct pollfd *fds, int nfds)
114 if (fds[0].revents&POLLERR) {
115 printf("tun_afterpoll: hup!\n");
117 if (fds[0].revents&POLLIN) {
118 BUF_ALLOC(st->buff,"tun_afterpoll");
119 buffer_init(st->buff,st->nl.max_start_pad);
120 l=read(st->fd,st->buff->start,st->buff->len-st->nl.max_start_pad);
122 fatal_perror("tun_afterpoll: read()");
125 fatal("tun_afterpoll: read()=0; device gone away?");
129 st->netlink_to_tunnel(&st->nl,st->buff);
130 BUF_ASSERT_FREE(st->buff);
135 static void tun_deliver_to_kernel(void *sst, struct buffer_if *buf)
140 BUF_ASSERT_USED(buf);
142 /* Log errors, so we can tell what's going on, but only once a
143 minute, so we don't flood the logs. Short writes count as
145 rc = write(st->fd,buf->start,buf->size);
146 if(rc != buf->size) {
147 static struct timeval last_report;
148 if(tv_now_global.tv_sec >= last_report.tv_sec + 60) {
151 "failed to deliver packet to tun device: %s\n",
155 "truncated packet delivered to tun device\n");
156 last_report = tv_now_global;
162 static bool_t tun_set_route(void *sst, struct netlink_client *routes)
165 string_t network, mask, secnetaddr;
166 struct subnet_list *nets;
170 if (routes->up == routes->kup) return False;
171 if (st->route_type==TUN_CONFIG_IOCTL) {
172 if (st->tun_flavour==TUN_FLAVOUR_STREAMS) {
173 fd=open(st->ip_path,O_RDWR);
175 fatal_perror("tun_set_route: can't open %s",st->ip_path);
178 fd=socket(PF_INET, SOCK_DGRAM, IPPROTO_IP);
180 fatal_perror("tun_set_route: socket()");
184 nets=routes->subnets;
185 secnetaddr=ipaddr_to_string(st->nl.secnet_address);
186 for (i=0; i<nets->entries; i++) {
187 network=ipaddr_to_string(nets->list[i].prefix);
188 mask=ipaddr_to_string(nets->list[i].mask);
189 Message(M_INFO,"%s: %s route %s/%d %s kernel routing table\n",
190 st->nl.name,routes->up?"adding":"deleting",network,
191 nets->list[i].len,routes->up?"to":"from");
192 switch (st->route_type) {
193 case TUN_CONFIG_LINUX:
194 sys_cmd(st->route_path,"route",routes->up?"add":"del",
195 "-net",network,"netmask",mask,
196 "gw",secnetaddr,(char *)0);
199 sys_cmd(st->route_path,"route",routes->up?"add":"del",
200 "-net",network,secnetaddr,mask,(char *)0);
202 case TUN_CONFIG_SOLARIS25:
203 sys_cmd(st->route_path,"route",routes->up?"add":"del",
204 network,secnetaddr,(char *)0);
206 case TUN_CONFIG_IOCTL:
208 /* darwin rtentry has a different format, use /sbin/route instead */
209 #if HAVE_NET_ROUTE_H && ! __APPLE__
211 struct sockaddr_in *sa;
215 sa=(struct sockaddr_in *)&rt.rt_dst;
216 sa->sin_family=AF_INET;
217 sa->sin_addr.s_addr=htonl(nets->list[i].prefix);
218 sa=(struct sockaddr_in *)&rt.rt_genmask;
219 sa->sin_family=AF_INET;
220 sa->sin_addr.s_addr=htonl(nets->list[i].mask);
221 sa=(struct sockaddr_in *)&rt.rt_gateway;
222 sa->sin_family=AF_INET;
223 sa->sin_addr.s_addr=htonl(st->nl.secnet_address);
224 rt.rt_flags=RTF_UP|RTF_GATEWAY;
225 action=routes->up?SIOCADDRT:SIOCDELRT;
226 if (ioctl(fd,action,&rt)<0) {
227 fatal_perror("tun_set_route: ioctl()");
230 fatal("tun_set_route: ioctl method not supported");
235 fatal("tun_set_route: unsupported route command type");
238 free(network); free(mask);
241 if (st->route_type==TUN_CONFIG_IOCTL) {
244 routes->kup=routes->up;
248 static void tun_phase_hook(void *sst, uint32_t newphase)
251 string_t hostaddr,secnetaddr;
253 struct netlink_client *r;
255 if (st->tun_flavour==TUN_FLAVOUR_BSD) {
256 if (st->search_for_if) {
260 dname=safe_malloc(strlen(st->device_path)+4,"tun_old_apply");
261 st->interface_name=safe_malloc(8,"tun_phase_hook");
263 for (i=0; i<255; i++) {
264 sprintf(dname,"%s%d",st->device_path,i);
265 if ((st->fd=open(dname,O_RDWR))>0) {
266 sprintf(st->interface_name,"tun%d",i);
267 Message(M_INFO,"%s: allocated network interface %s "
268 "through %s\n",st->nl.name,st->interface_name,
274 fatal("%s: unable to open any TUN device (%s...)",
275 st->nl.name,st->device_path);
278 st->fd=open(st->device_path,O_RDWR);
280 fatal_perror("%s: unable to open TUN device file %s",
281 st->nl.name,st->device_path);
284 } else if (st->tun_flavour==TUN_FLAVOUR_LINUX) {
285 #ifdef LINUX_TUN_SUPPORTED
288 /* New TUN interface: open the device, then do ioctl TUNSETIFF
289 to set or find out the network interface name. */
290 st->fd=open(st->device_path,O_RDWR);
292 fatal_perror("%s: can't open device file %s",st->nl.name,
296 ifr.ifr_flags = IFF_TUN | IFF_NO_PI; /* Just send/receive IP packets,
298 if (st->interface_name)
299 strncpy(ifr.ifr_name,st->interface_name,IFNAMSIZ);
300 if (ioctl(st->fd,TUNSETIFF,&ifr)<0) {
301 fatal_perror("%s: ioctl(TUNSETIFF)",st->nl.name);
303 if (!st->interface_name) {
304 st->interface_name=safe_malloc(strlen(ifr.ifr_name)+1,"tun_apply");
305 strcpy(st->interface_name,ifr.ifr_name);
306 Message(M_INFO,"%s: allocated network interface %s\n",st->nl.name,
310 fatal("tun_phase_hook: TUN_FLAVOUR_LINUX unexpected");
311 #endif /* LINUX_TUN_SUPPORTED */
312 } else if (st->tun_flavour==TUN_FLAVOUR_STREAMS) {
313 #ifdef HAVE_TUN_STREAMS
314 int tun_fd, if_fd, ppa=-1, ip_fd;
316 if ((ip_fd=open(st->ip_path, O_RDWR)) < 0) {
317 fatal_perror("%s: can't open %s",st->nl.name,st->ip_path);
319 if ((tun_fd=open(st->device_path,O_RDWR)) < 0) {
320 fatal_perror("%s: can't open %s",st->nl.name,st->device_path);
322 if ((ppa=ioctl(tun_fd,TUNNEWPPA,ppa)) < 0) {
323 fatal_perror("%s: can't assign new interface");
325 if ((if_fd=open(st->device_path,O_RDWR)) < 0) {
326 fatal_perror("%s: can't open %s (2)",st->nl.name,st->device_path);
328 if (ioctl(if_fd,I_PUSH,"ip") < 0) {
329 fatal_perror("%s: can't push IP module",st->nl.name);
331 if (ioctl(if_fd,IF_UNITSEL,(char *)&ppa) < 0) {
332 fatal_perror("%s: can't set ppa %d",st->nl.name,ppa);
334 if (ioctl(ip_fd, I_LINK, if_fd) < 0) {
335 fatal_perror("%s: can't link TUN device to IP",st->nl.name);
337 st->interface_name=safe_malloc(10,"tun_apply");
338 sprintf(st->interface_name,"tun%d",ppa);
341 fatal("tun_phase_hook: TUN_FLAVOUR_STREAMS unexpected");
342 #endif /* HAVE_TUN_STREAMS */
344 fatal("tun_phase_hook: unknown flavour of TUN");
346 /* All the networks we'll be using have been registered. Invoke ifconfig
347 to set the TUN device's address, and route to add routes to all
350 hostaddr=ipaddr_to_string(st->local_address);
351 secnetaddr=ipaddr_to_string(st->nl.secnet_address);
352 snprintf(mtu,sizeof(mtu),"%d",st->nl.mtu);
355 switch (st->ifconfig_type) {
356 case TUN_CONFIG_LINUX:
357 sys_cmd(st->ifconfig_path,"ifconfig",st->interface_name,
358 hostaddr,"netmask","255.255.255.255","-broadcast",
360 "pointopoint",secnetaddr,"mtu",mtu,"up",(char *)0);
363 sys_cmd(st->ifconfig_path,"ifconfig",st->interface_name,
364 hostaddr,"netmask","255.255.255.255",
365 secnetaddr,"mtu",mtu,"up",(char *)0);
367 case TUN_CONFIG_SOLARIS25:
368 sys_cmd(st->ifconfig_path,"ifconfig",st->interface_name,
369 hostaddr,secnetaddr,"mtu",mtu,"up",(char *)0);
371 case TUN_CONFIG_IOCTL:
372 #if HAVE_NET_IF_H && ! __APPLE__
376 struct sockaddr_in *sa;
377 fd=socket(PF_INET, SOCK_DGRAM, IPPROTO_IP);
379 /* Interface address */
380 strncpy(ifr.ifr_name,st->interface_name,IFNAMSIZ);
381 sa=(struct sockaddr_in *)&ifr.ifr_addr;
383 sa->sin_family=AF_INET;
384 sa->sin_addr.s_addr=htonl(st->local_address);
385 if (ioctl(fd,SIOCSIFADDR, &ifr)!=0) {
386 fatal_perror("tun_apply: SIOCSIFADDR");
388 #ifdef SIOCSIFNETMASK
390 strncpy(ifr.ifr_name,st->interface_name,IFNAMSIZ);
391 sa=(struct sockaddr_in *)&ifr.ifr_netmask;
393 sa->sin_family=AF_INET;
394 sa->sin_addr.s_addr=htonl(0xffffffff);
395 if (ioctl(fd,SIOCSIFNETMASK, &ifr)!=0) {
396 fatal_perror("tun_apply: SIOCSIFNETMASK");
399 /* Destination address (point-to-point) */
400 strncpy(ifr.ifr_name,st->interface_name,IFNAMSIZ);
401 sa=(struct sockaddr_in *)&ifr.ifr_dstaddr;
403 sa->sin_family=AF_INET;
404 sa->sin_addr.s_addr=htonl(st->nl.secnet_address);
405 if (ioctl(fd,SIOCSIFDSTADDR, &ifr)!=0) {
406 fatal_perror("tun_apply: SIOCSIFDSTADDR");
409 strncpy(ifr.ifr_name,st->interface_name,IFNAMSIZ);
410 ifr.ifr_mtu=st->nl.mtu;
411 if (ioctl(fd,SIOCSIFMTU, &ifr)!=0) {
412 fatal_perror("tun_apply: SIOCSIFMTU");
415 strncpy(ifr.ifr_name,st->interface_name,IFNAMSIZ);
416 ifr.ifr_flags=IFF_UP|IFF_POINTOPOINT|IFF_RUNNING|IFF_NOARP;
417 if (ioctl(fd,SIOCSIFFLAGS, &ifr)!=0) {
418 fatal_perror("tun_apply: SIOCSIFFLAGS");
424 fatal("tun_apply: ifconfig by ioctl() not supported");
425 #endif /* HAVE_NET_IF_H */
428 fatal("tun_apply: unsupported ifconfig method");
432 for (r=st->nl.clients; r; r=r->next) {
436 /* Register for poll() */
437 register_for_poll(st, tun_beforepoll, tun_afterpoll, 1, st->nl.name);
440 static list_t *tun_create(closure_t *self, struct cloc loc, dict_t *context,
441 list_t *args,uint32_t default_flavour)
446 string_t flavour,type;
448 st=safe_malloc(sizeof(*st),"tun_apply");
450 /* First parameter must be a dict */
451 item=list_elem(args,0);
452 if (!item || item->type!=t_dict)
453 cfgfatal(loc,"tun","parameter must be a dictionary\n");
455 dict=item->data.dict;
457 st->netlink_to_tunnel=
458 netlink_init(&st->nl,st,loc,dict,
459 "netlink-tun",tun_set_route,tun_deliver_to_kernel);
461 flavour=dict_read_string(dict,"flavour",False,"tun-netlink",loc);
463 st->tun_flavour=string_to_word(flavour,loc,flavours,"tun-flavour");
465 st->tun_flavour=default_flavour;
467 st->device_path=dict_read_string(dict,"device",False,"tun-netlink",loc);
468 st->ip_path=dict_read_string(dict,"ip-path",False,"tun-netlink",loc);
469 st->interface_name=dict_read_string(dict,"interface",False,
471 st->search_for_if=dict_read_bool(dict,"interface-search",False,
472 "tun-netlink",loc,st->device_path==NULL);
474 type=dict_read_string(dict,"ifconfig-type",False,"tun-netlink",loc);
475 if (type) st->ifconfig_type=string_to_word(type,loc,config_types,
477 else st->ifconfig_type=TUN_CONFIG_GUESS;
478 st->ifconfig_path=dict_read_string(dict,"ifconfig-path",False,
481 type=dict_read_string(dict,"route-type",False,"tun-netlink",loc);
482 if (type) st->route_type=string_to_word(type,loc,config_types,
484 else st->route_type=TUN_CONFIG_GUESS;
485 st->route_path=dict_read_string(dict,"route-path",False,"tun-netlink",loc);
487 st->buff=find_cl_if(dict,"buffer",CL_BUFFER,True,"tun-netlink",loc);
488 st->local_address=string_item_to_ipaddr(
489 dict_find_item(dict,"local-address", True, "netlink", loc),"netlink");
491 if (st->tun_flavour==TUN_FLAVOUR_GUESS) {
492 /* If we haven't been told what type of TUN we're using, take
493 a guess based on the system details. */
496 fatal_perror("tun_create: uname");
498 if (strcmp(u.sysname,"Linux")==0) {
499 st->tun_flavour=TUN_FLAVOUR_LINUX;
500 } else if (strcmp(u.sysname,"SunOS")==0) {
501 st->tun_flavour=TUN_FLAVOUR_STREAMS;
502 } else if (strcmp(u.sysname,"FreeBSD")==0
503 || strcmp(u.sysname,"Darwin")==0) {
504 st->tun_flavour=TUN_FLAVOUR_BSD;
507 if (st->tun_flavour==TUN_FLAVOUR_GUESS) {
508 cfgfatal(loc,"tun","cannot guess which type of TUN is in use; "
509 "specify the flavour explicitly\n");
512 if (st->ifconfig_type==TUN_CONFIG_GUESS) {
513 switch (st->tun_flavour) {
514 case TUN_FLAVOUR_LINUX:
515 st->ifconfig_type=TUN_CONFIG_IOCTL;
517 case TUN_FLAVOUR_BSD:
519 /* XXX on Linux we still want TUN_CONFIG_IOCTL. Perhaps we can
520 use this on BSD too. */
521 st->ifconfig_type=TUN_CONFIG_IOCTL;
523 st->ifconfig_type=TUN_CONFIG_BSD;
526 case TUN_FLAVOUR_STREAMS:
527 st->ifconfig_type=TUN_CONFIG_BSD;
531 if (st->route_type==TUN_CONFIG_GUESS)
532 st->route_type=st->ifconfig_type;
534 if (st->ifconfig_type==TUN_CONFIG_GUESS) {
535 cfgfatal(loc,"tun","cannot guess which ifconfig method to use\n");
537 if (st->route_type==TUN_CONFIG_GUESS) {
538 cfgfatal(loc,"tun","cannot guess which route method to use\n");
541 if (st->ifconfig_type==TUN_CONFIG_IOCTL && st->ifconfig_path) {
542 cfgfatal(loc,"tun","ifconfig-type \"ioctl\" is incompatible with "
545 if (st->route_type==TUN_CONFIG_IOCTL && st->route_path) {
546 cfgfatal(loc,"tun","route-type \"ioctl\" is incompatible with "
550 Message(M_DEBUG_CONFIG,"%s: tun flavour %s\n",st->nl.name,
551 tun_flavour_str(st->tun_flavour));
552 switch (st->tun_flavour) {
553 case TUN_FLAVOUR_BSD:
554 if (!st->device_path) st->device_path="/dev/tun";
556 case TUN_FLAVOUR_LINUX:
557 if (!st->device_path) st->device_path="/dev/net/tun";
559 case TUN_FLAVOUR_STREAMS:
560 if (!st->device_path) st->device_path="/dev/tun";
561 if (st->interface_name) cfgfatal(loc,"tun","interface name cannot "
562 "be specified with STREAMS TUN\n");
566 if (!st->ip_path) st->ip_path="/dev/ip";
567 if (!st->ifconfig_path) st->ifconfig_path="ifconfig";
568 if (!st->route_path) st->route_path="route";
570 #ifndef HAVE_TUN_STREAMS
571 if (st->tun_flavour==TUN_FLAVOUR_STREAMS) {
572 cfgfatal(loc,"tun","TUN flavour STREAMS unsupported in this build "
576 #ifndef LINUX_TUN_SUPPORTED
577 if (st->tun_flavour==TUN_FLAVOUR_LINUX) {
578 cfgfatal(loc,"tun","TUN flavour LINUX unsupported in this build "
583 /* Old TUN interface: the network interface name depends on which
584 /dev/tunX file we open. If 'interface-search' is set to true, treat
585 'device' as the prefix and try numbers from 0--255. If it's set
586 to false, treat 'device' as the whole name, and require than an
587 appropriate interface name be specified. */
588 if (st->tun_flavour==TUN_FLAVOUR_BSD) {
589 if (st->search_for_if && st->interface_name) {
590 cfgfatal(loc,"tun","you may not specify an interface name "
591 "in interface-search mode\n");
593 if (!st->search_for_if && !st->interface_name) {
594 cfgfatal(loc,"tun","you must specify an interface name "
595 "when you explicitly specify a TUN device file\n");
599 add_hook(PHASE_GETRESOURCES,tun_phase_hook,st);
601 return new_closure(&st->nl.cl);
604 static list_t *tun_apply(closure_t *self, struct cloc loc, dict_t *context,
607 return tun_create(self,loc,context,args,TUN_FLAVOUR_GUESS);
610 static list_t *tun_bsd_apply(closure_t *self, struct cloc loc, dict_t *context,
613 Message(M_WARNING,"(%s,%d): obsolete use of tun-old; replace with tun "
614 "and specify flavour \"bsd\".\n",loc.file,loc.line);
615 return tun_create(self,loc,context,args,TUN_FLAVOUR_BSD);
618 void tun_module(dict_t *dict)
620 add_closure(dict,"tun",tun_apply);
621 add_closure(dict,"tun-old",tun_bsd_apply);