Commit | Line | Data |
---|---|---|
50c74957 | 1 | /* -*-c-*- |
50c74957 | 2 | * |
3 | * An evil proxy for TrIPE | |
4 | * | |
5 | * (c) 2001 Straylight/Edgeware | |
6 | */ | |
7 | ||
e04c2d50 | 8 | /*----- Licensing notice --------------------------------------------------* |
50c74957 | 9 | * |
10 | * This file is part of Trivial IP Encryption (TrIPE). | |
11 | * | |
11ad66c2 MW |
12 | * TrIPE is free software: you can redistribute it and/or modify it under |
13 | * the terms of the GNU General Public License as published by the Free | |
14 | * Software Foundation; either version 3 of the License, or (at your | |
15 | * option) any later version. | |
e04c2d50 | 16 | * |
11ad66c2 MW |
17 | * TrIPE is distributed in the hope that it will be useful, but WITHOUT |
18 | * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or | |
19 | * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License | |
20 | * for more details. | |
e04c2d50 | 21 | * |
50c74957 | 22 | * You should have received a copy of the GNU General Public License |
11ad66c2 | 23 | * along with TrIPE. If not, see <https://www.gnu.org/licenses/>. |
50c74957 | 24 | */ |
25 | ||
50c74957 | 26 | /*----- Header files ------------------------------------------------------*/ |
27 | ||
28 | #include "config.h" | |
29 | ||
30 | #include <assert.h> | |
31 | #include <errno.h> | |
32 | #include <stdio.h> | |
33 | #include <stdlib.h> | |
34 | #include <string.h> | |
35 | #include <time.h> | |
36 | ||
37 | #include <sys/types.h> | |
38 | #include <sys/time.h> | |
39 | #include <unistd.h> | |
40 | #include <fcntl.h> | |
41 | ||
42 | #include <sys/socket.h> | |
43 | #include <netinet/in.h> | |
44 | #include <arpa/inet.h> | |
45 | #include <netdb.h> | |
46 | ||
47 | #include <mLib/alloc.h> | |
48 | #include <mLib/dstr.h> | |
49 | #include <mLib/fdflags.h> | |
50 | #include <mLib/mdwopt.h> | |
51 | #include <mLib/quis.h> | |
52 | #include <mLib/report.h> | |
53 | #include <mLib/sel.h> | |
54 | #include <mLib/sub.h> | |
55 | #include <mLib/tv.h> | |
56 | ||
c953f4b5 | 57 | #include <catacomb/buf.h> |
58 | ||
50c74957 | 59 | #include <catacomb/key.h> |
60 | ||
61 | #include <catacomb/mp.h> | |
50c74957 | 62 | #include <catacomb/mprand.h> |
63 | #include <catacomb/dh.h> | |
64 | ||
9f90c1f6 | 65 | #include <catacomb/chacha20.h> |
50c74957 | 66 | #include <catacomb/noise.h> |
67 | #include <catacomb/rand.h> | |
50c74957 | 68 | |
23df0e5b MW |
69 | #include "util.h" |
70 | ||
50c74957 | 71 | /*----- Data structures ---------------------------------------------------*/ |
72 | ||
73 | typedef struct peer { | |
74 | sel_file sf; | |
50c74957 | 75 | const char *name; |
76 | struct filter *f; | |
77 | } peer; | |
78 | ||
79 | typedef struct filter { | |
80 | struct filter *next; | |
81 | peer *p_from, *p_to; | |
82 | void (*func)(struct filter */*f*/, const octet */*buf*/, size_t /*sz*/); | |
83 | void *state; | |
84 | } filter; | |
85 | ||
86 | typedef struct qnode { | |
87 | octet *buf; | |
88 | size_t sz; | |
89 | } qnode; | |
90 | ||
91 | /*----- Static variables --------------------------------------------------*/ | |
92 | ||
93 | #define PKBUFSZ 65536 | |
94 | ||
95 | static sel_state sel; | |
96 | static peer peers[2]; | |
97 | static unsigned npeer = 0; | |
98 | static key_file keys; | |
99 | static grand *rng; | |
a8ce36a6 | 100 | static const char *delim = ":"; |
50c74957 | 101 | |
102 | #define PASS(f, buf, sz) ((f) ? (f)->func((f), (buf), (sz)) : (void)0) | |
103 | #define RND(i) (rng->ops->range(rng, (i))) | |
104 | ||
105 | /*----- Peer management ---------------------------------------------------*/ | |
106 | ||
107 | static void dopacket(int fd, unsigned mode, void *vv) | |
108 | { | |
109 | octet buf[PKBUFSZ]; | |
110 | peer *p = vv; | |
111 | int r = read(fd, buf, sizeof(buf)); | |
112 | if (r >= 0) { | |
113 | printf("recv from `%s'\n", p->name); | |
114 | PASS(p->f, buf, r); | |
115 | } | |
116 | } | |
117 | ||
7f77e37b | 118 | static void addpeer_common(const char *cmd, int af, unsigned ac, char **av) |
50c74957 | 119 | { |
7f77e37b MW |
120 | struct addrinfo aihint = { 0 }, *ai0, *ai1; |
121 | int len = PKBUFSZ, yes = 1; | |
a23e7183 MW |
122 | const char *outf, *serv; |
123 | FILE *fp; | |
124 | union { | |
125 | struct sockaddr sa; | |
126 | struct sockaddr_in sin; | |
127 | struct sockaddr_in6 sin6; | |
128 | } addr; | |
129 | socklen_t salen; | |
7f77e37b | 130 | int err; |
50c74957 | 131 | peer *p; |
a23e7183 | 132 | int fd, port; |
50c74957 | 133 | |
7f77e37b | 134 | if (ac != 4) die(1, "syntax: %s:NAME:PORT:ADDR:PORT", cmd); |
6dbded74 | 135 | if (!key_bytag(&keys, av[0])) die(1, "no key named `%s'", av[0]); |
50c74957 | 136 | p = &peers[npeer++]; |
137 | p->name = xstrdup(av[0]); | |
7f77e37b MW |
138 | aihint.ai_family = af; |
139 | aihint.ai_socktype = SOCK_DGRAM; | |
140 | aihint.ai_flags = AI_ADDRCONFIG; | |
141 | if ((err = getaddrinfo(av[2], av[3], &aihint, &ai1)) != 0) | |
142 | die(1, "getaddrinfo(`%s', `%s'): %s", av[2], av[3], gai_strerror(err)); | |
a23e7183 MW |
143 | if (*av[1] == '?') { serv = "0"; outf = av[1] + 1; } |
144 | else { serv = av[1]; outf = 0; } | |
7f77e37b MW |
145 | aihint.ai_family = ai1->ai_family; |
146 | aihint.ai_flags = AI_ADDRCONFIG | AI_PASSIVE; | |
a23e7183 | 147 | if ((err = getaddrinfo(0, serv, &aihint, &ai0)) != 0) |
7f77e37b MW |
148 | die(1, "getaddrinfo(passive, `%s'): %s", av[1], gai_strerror(err)); |
149 | if ((fd = socket(ai1->ai_family, SOCK_DGRAM, ai1->ai_protocol)) < 0) | |
50c74957 | 150 | die(1, "socket: %s", strerror(errno)); |
7f77e37b MW |
151 | if (ai1->ai_family == AF_INET6) { |
152 | if (setsockopt(fd, IPPROTO_IPV6, IPV6_V6ONLY, &yes, sizeof(yes))) | |
153 | die(1, "setsockopt: %s", strerror(errno)); | |
154 | } | |
155 | if (bind(fd, ai0->ai_addr, ai0->ai_addrlen)) | |
50c74957 | 156 | die(1, "bind: %s", strerror(errno)); |
50c74957 | 157 | if (setsockopt(fd, SOL_SOCKET, SO_RCVBUF, &len, sizeof(len)) || |
158 | setsockopt(fd, SOL_SOCKET, SO_SNDBUF, &len, sizeof(len))) | |
159 | die(1, "setsockopt: %s", strerror(errno)); | |
7f77e37b | 160 | if (connect(fd, ai1->ai_addr, ai1->ai_addrlen)) |
50c74957 | 161 | die(1, "connect: %s", strerror(errno)); |
a23e7183 MW |
162 | if (outf) { |
163 | salen = sizeof(addr); | |
164 | if (getsockname(fd, &addr.sa, &salen)) | |
165 | die(1, "getsockname: %s", strerror(errno)); | |
166 | switch (addr.sa.sa_family) { | |
167 | case AF_INET: port = ntohs(addr.sin.sin_port); break; | |
168 | case AF_INET6: port = ntohs(addr.sin6.sin6_port); break; | |
169 | default: assert(0); | |
170 | } | |
171 | fp = fopen(outf, "w"); | |
172 | if (!fp) die(1, "fopen(%s): %s", outf, strerror(errno)); | |
173 | fprintf(fp, "%d\n", port); | |
174 | fclose(fp); | |
175 | } | |
50c74957 | 176 | sel_initfile(&sel, &p->sf, fd, SEL_READ, dopacket, p); |
177 | sel_addfile(&p->sf); | |
7f77e37b | 178 | freeaddrinfo(ai0); freeaddrinfo(ai1); |
50c74957 | 179 | } |
180 | ||
7f77e37b MW |
181 | static void addpeer(unsigned ac, char **av) |
182 | { addpeer_common("peer", AF_UNSPEC, ac, av); } | |
183 | static void addpeer4(unsigned ac, char **av) | |
184 | { addpeer_common("peer4", AF_INET, ac, av); } | |
185 | static void addpeer6(unsigned ac, char **av) | |
186 | { addpeer_common("peer6", AF_INET6, ac, av); } | |
187 | ||
50c74957 | 188 | /*----- Fork filter -------------------------------------------------------*/ |
189 | ||
190 | typedef struct forknode { | |
191 | struct forknode *next; | |
192 | filter *f; | |
193 | } forknode; | |
194 | ||
195 | typedef struct forkfilt { | |
196 | const char *name; | |
197 | forknode *fn; | |
198 | } forkfilt; | |
199 | ||
200 | static void dofork(filter *f, const octet *buf, size_t sz) | |
201 | { | |
202 | forkfilt *ff = f->state; | |
203 | forknode *fn; | |
204 | unsigned i = 0; | |
205 | ||
206 | ff = f->state; | |
207 | for (fn = ff->fn; fn; fn = fn->next) { | |
208 | printf("fork branch %u of fork `%s'\n", i++, ff->name); | |
209 | PASS(fn->f, buf, sz); | |
210 | } | |
211 | printf("fork branch %u of fork `%s'\n", i++, ff->name); | |
212 | PASS(f->next, buf, sz); | |
213 | } | |
214 | ||
215 | static void addfork(filter *f, unsigned ac, char **av) | |
216 | { | |
217 | forkfilt *ff; | |
6dbded74 | 218 | if (ac != 1) die(1, "syntax: filt:fork:NAME"); |
50c74957 | 219 | ff = CREATE(forkfilt); |
220 | ff->name = xstrdup(av[0]); | |
221 | ff->fn = 0; | |
222 | f->func = dofork; | |
223 | f->state = ff; | |
224 | } | |
225 | ||
226 | static void nextfork(unsigned ac, char **av) | |
227 | { | |
c953f4b5 | 228 | unsigned i, j; |
50c74957 | 229 | filter *f; |
230 | forkfilt *ff; | |
231 | forknode *fn, **ffn; | |
232 | peer *p; | |
233 | ||
6dbded74 | 234 | if (ac < 1) die(1, "syntax: next:NAME:..."); |
50c74957 | 235 | for (i = 0; i < 2; i++) { |
236 | p = &peers[i]; | |
237 | for (f = p->f; f; f = f->next) { | |
6dbded74 | 238 | if (f->func != dofork) continue; |
50c74957 | 239 | ff = f->state; |
6dbded74 MW |
240 | for (j = 0; j < ac; j++) |
241 | if (strcmp(av[j], ff->name) == 0) goto match; | |
c953f4b5 | 242 | continue; |
243 | match: | |
50c74957 | 244 | fn = CREATE(forknode); |
6dbded74 | 245 | for (ffn = &ff->fn; *ffn; ffn = &(*ffn)->next); |
50c74957 | 246 | fn->f = f->next; |
247 | f->next = 0; | |
248 | fn->next = 0; | |
249 | *ffn = fn; | |
250 | } | |
251 | } | |
252 | } | |
253 | ||
254 | /*----- Corrupt filter ----------------------------------------------------*/ | |
255 | ||
256 | typedef struct corrupt { | |
257 | unsigned p_corrupt; | |
258 | } corrupt; | |
259 | ||
260 | static void docorrupt(filter *f, const octet *buf, size_t sz) | |
261 | { | |
262 | corrupt *c = f->state; | |
263 | octet b[PKBUFSZ]; | |
264 | memcpy(b, buf, sz); | |
265 | ||
266 | while (!RND(c->p_corrupt)) { | |
267 | puts("corrupt packet"); | |
268 | b[RND(sz)] ^= RND(256); | |
269 | } | |
270 | PASS(f->next, b, sz); | |
271 | } | |
272 | ||
273 | static void addcorrupt(filter *f, unsigned ac, char **av) | |
274 | { | |
275 | corrupt *c; | |
6dbded74 | 276 | if (ac > 1) die(1, "syntax: filt:corrupt[:P-CORRUPT]"); |
50c74957 | 277 | c = CREATE(corrupt); |
6dbded74 MW |
278 | if (ac > 0) c->p_corrupt = atoi(av[0]); |
279 | else c->p_corrupt = 5; | |
50c74957 | 280 | f->state = c; |
281 | f->func = docorrupt; | |
282 | } | |
283 | ||
a2e06ed5 MW |
284 | /*----- Drop filter -------------------------------------------------------*/ |
285 | ||
286 | typedef struct drop { | |
287 | unsigned p_drop; | |
288 | } drop; | |
289 | ||
290 | static void dodrop(filter *f, const octet *buf, size_t sz) | |
291 | { | |
292 | drop *d = f->state; | |
293 | ||
6dbded74 MW |
294 | if (!RND(d->p_drop)) puts("drop packet"); |
295 | else PASS(f->next, buf, sz); | |
a2e06ed5 MW |
296 | } |
297 | ||
298 | static void adddrop(filter *f, unsigned ac, char **av) | |
299 | { | |
300 | drop *d; | |
6dbded74 | 301 | if (ac > 1) die(1, "syntax: filt:drop[:P-DROP]"); |
a2e06ed5 | 302 | d = CREATE(drop); |
6dbded74 MW |
303 | if (ac > 0) d->p_drop = atoi(av[0]); |
304 | else d->p_drop = 5; | |
a2e06ed5 MW |
305 | f->state = d; |
306 | f->func = dodrop; | |
307 | } | |
308 | ||
50c74957 | 309 | /*----- Delay filter ------------------------------------------------------*/ |
310 | ||
311 | typedef struct delaynode { | |
312 | unsigned flag; | |
313 | sel_timer tm; | |
314 | unsigned i; | |
315 | struct delay *d; | |
316 | octet *buf; | |
317 | size_t sz; | |
318 | unsigned seq; | |
319 | } delaynode; | |
320 | ||
321 | typedef struct delay { | |
322 | unsigned max, n; | |
323 | unsigned long t; | |
324 | unsigned p_replay; | |
325 | filter *f; | |
326 | delaynode *q; | |
327 | } delay; | |
328 | ||
329 | static void dtimer(struct timeval *tv, void *vv); | |
330 | ||
331 | static void dinsert(delaynode *dn) | |
332 | { | |
333 | struct timeval tv; | |
334 | sel_timer *ta, *tb; | |
335 | unsigned long tdelta = RND(dn->d->t); | |
336 | gettimeofday(&tv, 0); | |
337 | TV_ADDL(&tv, &tv, 0, tdelta); | |
338 | assert(!dn->flag); | |
339 | sel_addtimer(&sel, &dn->tm, &tv, dtimer, dn); | |
340 | dn->flag = 1; | |
341 | for (ta = tb = sel.timers; ta; ta = ta->next) { | |
342 | ta = ta->next; if (!ta) break; assert(ta != tb); | |
343 | ta = ta->next; if (!ta) break; assert(ta != tb); | |
344 | tb = tb->next; | |
345 | } | |
346 | printf(" delay %lu usecs", tdelta); | |
347 | } | |
348 | ||
349 | static void dsend(delaynode *dn, unsigned force) | |
350 | { | |
351 | delay *d = dn->d; | |
352 | delaynode *ddn; | |
6dbded74 MW |
353 | unsigned i; |
354 | ||
50c74957 | 355 | fputs(" send...\n", stdout); |
356 | assert(dn->buf); | |
357 | PASS(d->f->next, dn->buf, dn->sz); | |
358 | fputs("delay ...", stdout); | |
359 | if (!force) | |
360 | dinsert(dn); | |
361 | else { | |
362 | xfree(dn->buf); | |
363 | dn->buf = 0; | |
364 | d->n--; | |
365 | if (dn->i < d->n) { | |
366 | ddn = &d->q[d->n]; | |
367 | sel_rmtimer(&ddn->tm); | |
368 | sel_addtimer(&sel, &dn->tm, &ddn->tm.tv, dtimer, dn); | |
369 | dn->flag = 1; | |
370 | dn->buf = ddn->buf; | |
371 | dn->sz = ddn->sz; | |
372 | dn->seq = ddn->seq; | |
373 | ddn->buf = 0; | |
374 | ddn->flag = 0; | |
375 | printf(" move id %u from slot %u to slot %u", ddn->seq, ddn->i, dn->i); | |
376 | } | |
6dbded74 | 377 | for (i = 0; i < d->n; i++) assert(d->q[i].buf); |
50c74957 | 378 | fputs(" remove", stdout); |
379 | } | |
380 | } | |
381 | ||
382 | static void dtimer(struct timeval *tv, void *vv) | |
383 | { | |
384 | delaynode *dn = vv; | |
385 | printf("delay timer peer `%s' id %u slot %u", | |
386 | dn->d->f->p_from->name, dn->seq, dn->i); | |
387 | dn->flag = 0; | |
388 | dsend(dn, RND(dn->d->p_replay)); | |
389 | fputc('\n', stdout); | |
390 | } | |
391 | ||
392 | static void dodelay(filter *f, const octet *buf, size_t sz) | |
393 | { | |
394 | delay *d = f->state; | |
395 | delaynode *dn; | |
396 | static unsigned seq = 0; | |
397 | ||
398 | fputs("delay", stdout); | |
399 | if (d->n == d->max) { | |
400 | dn = &d->q[RND(d->n)]; | |
401 | printf(" force uid %u", dn->seq); | |
402 | sel_rmtimer(&dn->tm); | |
403 | dn->flag = 0; | |
404 | dsend(dn, 1); | |
405 | fputc(';', stdout); | |
406 | } | |
407 | dn = &d->q[d->n++]; | |
408 | dn->seq = seq++; | |
409 | printf(" new id %u in slot %u", dn->seq, dn->i); | |
410 | dn->buf = xmalloc(sz); | |
411 | dn->sz = sz; | |
412 | memcpy(dn->buf, buf, sz); | |
413 | dinsert(dn); | |
414 | fputc('\n', stdout); | |
415 | } | |
416 | ||
417 | static void adddelay(filter *f, unsigned ac, char **av) | |
418 | { | |
419 | delay *d; | |
420 | unsigned i; | |
421 | ||
6dbded74 | 422 | if (ac < 1 || ac > 3) die(1, "syntax: filt:delay:QLEN[:MILLIS:P-REPLAY]"); |
50c74957 | 423 | d = CREATE(delay); |
424 | d->max = atoi(av[0]); | |
6dbded74 MW |
425 | if (ac > 1) d->t = strtoul(av[1], 0, 10); |
426 | else d->t = 100; | |
50c74957 | 427 | d->t *= 1000; |
6dbded74 MW |
428 | if (ac > 2) d->p_replay = atoi(av[2]); |
429 | else d->p_replay = 20; | |
50c74957 | 430 | d->n = 0; |
431 | d->q = xmalloc(d->max * sizeof(delaynode)); | |
432 | d->f = f; | |
433 | f->state = d; | |
434 | f->func = dodelay; | |
435 | for (i = 0; i < d->max; i++) { | |
436 | d->q[i].d = d; | |
437 | d->q[i].i = i; | |
438 | d->q[i].buf = 0; | |
439 | d->q[i].flag = 0; | |
440 | } | |
441 | } | |
442 | ||
443 | /*----- Filters -----------------------------------------------------------*/ | |
444 | ||
445 | static void dosend(filter *f, const octet *buf, size_t sz) | |
446 | { | |
447 | printf("send to `%s'\n", f->p_to->name); | |
99735357 | 448 | DISCARD(write(f->p_to->sf.fd, buf, sz)); |
50c74957 | 449 | } |
450 | ||
451 | static void addsend(filter *f, unsigned ac, char **av) | |
452 | { | |
6dbded74 | 453 | if (ac) die(1, "syntax: filt:send"); |
50c74957 | 454 | f->func = dosend; |
455 | } | |
456 | ||
457 | const struct filtab { | |
458 | const char *name; | |
459 | void (*func)(filter */*f*/, unsigned /*ac*/, char **/*av*/); | |
460 | } filtab[] = { | |
461 | { "send", addsend }, | |
462 | { "fork", addfork }, | |
463 | { "delay", adddelay }, | |
a2e06ed5 | 464 | { "drop", adddrop }, |
50c74957 | 465 | { "corrupt", addcorrupt }, |
466 | { 0, 0 } | |
467 | }; | |
468 | ||
469 | static void dofilter(peer *from, peer *to, unsigned ac, char **av) | |
470 | { | |
471 | filter **ff, *f = CREATE(filter); | |
472 | const struct filtab *ft; | |
6dbded74 | 473 | if (ac < 1) die(1, "syntax: {l,r,}filt:NAME:..."); |
50c74957 | 474 | f->next = 0; |
475 | f->p_from = from; | |
476 | f->p_to = to; | |
477 | f->state = 0; | |
6dbded74 | 478 | for (ff = &from->f; *ff; ff = &(*ff)->next); |
50c74957 | 479 | *ff = f; |
6dbded74 MW |
480 | for (ft = filtab; ft->name; ft++) |
481 | if (strcmp(av[0], ft->name) == 0) | |
482 | { ft->func(f, ac - 1, av + 1); return; } | |
50c74957 | 483 | die(1, "unknown filter `%s'", av[0]); |
484 | } | |
485 | ||
486 | /*----- Flooding ----------------------------------------------------------*/ | |
487 | ||
488 | typedef struct flood { | |
489 | peer *p; | |
490 | unsigned type; | |
491 | size_t sz; | |
492 | unsigned long t; | |
493 | sel_timer tm; | |
494 | } flood; | |
495 | ||
496 | static void setflood(flood *f); | |
497 | ||
498 | static void floodtimer(struct timeval *tv, void *vv) | |
499 | { | |
500 | flood *f = vv; | |
501 | octet buf[PKBUFSZ]; | |
502 | size_t sz; | |
503 | ||
504 | sz = RND(f->sz); | |
505 | sz += RND(f->sz); | |
506 | sz += RND(f->sz); | |
507 | sz += RND(f->sz); | |
508 | sz /= 2; | |
509 | ||
510 | rng->ops->fill(rng, buf, sz); | |
6dbded74 | 511 | if (f->type < 0x100) buf[0] = f->type; |
50c74957 | 512 | puts("flood packet"); |
513 | PASS(f->p->f, buf, sz); | |
514 | setflood(f); | |
515 | } | |
e04c2d50 | 516 | |
50c74957 | 517 | static void setflood(flood *f) |
518 | { | |
519 | struct timeval tv; | |
520 | gettimeofday(&tv, 0); | |
521 | TV_ADDL(&tv, &tv, 0, RND(f->t)); | |
522 | sel_addtimer(&sel, &f->tm, &tv, floodtimer, f); | |
523 | } | |
524 | ||
525 | static void doflood(peer *p, unsigned ac, char **av) | |
526 | { | |
527 | flood *f; | |
6dbded74 | 528 | if (ac > 3) die(1, "syntax: flood[:TYPE:MILLIS:SIZE]"); |
50c74957 | 529 | f = CREATE(flood); |
530 | f->p = p; | |
6dbded74 MW |
531 | if (ac > 0) f->type = strtoul(av[0], 0, 16); |
532 | else f->type = 0x100; | |
533 | if (ac > 1) f->t = atoi(av[1]); | |
534 | else f->t = 10; | |
535 | if (ac > 2) f->sz = atoi(av[2]); | |
536 | else f->sz = 128; | |
50c74957 | 537 | f->t *= 1000; |
538 | setflood(f); | |
539 | } | |
540 | ||
541 | /*----- Configuration commands --------------------------------------------*/ | |
542 | ||
543 | static void parse(char *p); | |
544 | ||
545 | static void addflood(unsigned ac, char **av) { | |
546 | doflood(&peers[0], ac, av); | |
547 | doflood(&peers[1], ac, av); | |
548 | } | |
549 | static void addlflood(unsigned ac, char **av) { | |
550 | doflood(&peers[0], ac, av); | |
551 | } | |
552 | static void addrflood(unsigned ac, char **av) { | |
553 | doflood(&peers[1], ac, av); | |
554 | } | |
555 | ||
556 | static void addfilter(unsigned ac, char **av) { | |
557 | dofilter(&peers[0], &peers[1], ac, av); | |
558 | dofilter(&peers[1], &peers[0], ac, av); | |
559 | } | |
560 | static void addlfilter(unsigned ac, char **av) { | |
561 | dofilter(&peers[0], &peers[1], ac, av); | |
562 | } | |
563 | static void addrfilter(unsigned ac, char **av) { | |
564 | dofilter(&peers[1], &peers[0], ac, av); | |
565 | } | |
566 | ||
567 | static void include(unsigned ac, char **av) | |
568 | { | |
569 | FILE *fp; | |
570 | dstr d = DSTR_INIT; | |
6dbded74 | 571 | if (!ac) die(1, "syntax: include:FILE:..."); |
50c74957 | 572 | while (*av) { |
573 | if ((fp = fopen(*av, "r")) == 0) | |
574 | die(1, "fopen `%s': %s", *av, strerror(errno)); | |
6dbded74 | 575 | while (dstr_putline(&d, fp) != EOF) { parse(d.buf); DRESET(&d); } |
50c74957 | 576 | fclose(fp); |
577 | av++; | |
578 | } | |
579 | } | |
580 | ||
581 | const struct cmdtab { | |
582 | const char *name; | |
583 | void (*func)(unsigned /*ac*/, char **/*av*/); | |
584 | } cmdtab[] = { | |
585 | { "peer", addpeer }, | |
7f77e37b MW |
586 | { "peer4", addpeer4 }, |
587 | { "peer6", addpeer6 }, | |
50c74957 | 588 | { "include", include }, |
589 | { "filt", addfilter }, | |
590 | { "lfilt", addlfilter }, | |
591 | { "rfilt", addrfilter }, | |
592 | { "next", nextfork }, | |
593 | { "flood", addflood }, | |
594 | { "lflood", addlflood }, | |
595 | { "rflood", addrflood }, | |
596 | { 0, 0 } | |
597 | }; | |
598 | ||
599 | #define AVMAX 16 | |
600 | ||
601 | static void parse(char *p) | |
602 | { | |
603 | char *v[AVMAX]; | |
604 | unsigned c = 0; | |
605 | const struct cmdtab *ct; | |
606 | ||
a8ce36a6 | 607 | p = strtok(p, delim); |
6dbded74 | 608 | if (!p || *p == '#') return; |
50c74957 | 609 | do { |
610 | v[c++] = p; | |
a8ce36a6 | 611 | p = strtok(0, delim); |
50c74957 | 612 | } while (p && c < AVMAX - 1); |
613 | v[c] = 0; | |
614 | for (ct = cmdtab; ct->name; ct++) { | |
615 | if (strcmp(ct->name, v[0]) == 0) { | |
616 | ct->func(c - 1, v + 1); | |
617 | return; | |
618 | } | |
619 | } | |
620 | die(1, "unknown command `%s'", v[0]); | |
621 | } | |
622 | ||
623 | /*----- Main driver -------------------------------------------------------*/ | |
624 | ||
625 | static void version(FILE *fp) | |
f98df549 | 626 | { pquis(fp, "$, TrIPE version " VERSION "\n"); } |
50c74957 | 627 | |
628 | static void usage(FILE *fp) | |
a8ce36a6 | 629 | { pquis(fp, "Usage: $ [-d CHAR] [-k KEYRING] DIRECTIVE...\n"); } |
50c74957 | 630 | |
631 | static void help(FILE *fp) | |
632 | { | |
633 | version(fp); | |
634 | putc('\n', fp); | |
635 | usage(fp); | |
2d752320 | 636 | fputs("\n\ |
3cdc3f3a | 637 | Options:\n\ |
638 | \n\ | |
639 | -h, --help Show this help text.\n\ | |
640 | -v, --version Show the version number.\n\ | |
641 | -u, --usage Show terse usage summary.\n\ | |
642 | \n\ | |
a8ce36a6 | 643 | -d, --delimiter=CHAR Use CHAR rather than `:' as delimiter.\n\ |
3cdc3f3a | 644 | -k, --keyring=FILE Fetch keys from FILE.\n\ |
645 | \n\ | |
2d752320 | 646 | Directives:\n\ |
7f77e37b | 647 | peer{,4,6}:NAME:LOCAL-PORT:REMOTE-ADDR:REMOTE-PORT\n\ |
2d752320 | 648 | include:FILE\n\ |
649 | {,l,r}filt:FILTER:ARGS:...\n\ | |
650 | next:TAG\n\ | |
651 | {,l,r}flood:TYPE:MILLIS:SIZE\n\ | |
652 | \n\ | |
653 | Filters:\n\ | |
654 | send\n\ | |
655 | fork:TAG\n\ | |
656 | delay:QLEN[:MILLIS:P-REPLAY]\n\ | |
a2e06ed5 | 657 | drop[:P-DROP]\n\ |
2d752320 | 658 | corrupt[:P-CORRUPT]\n", |
659 | fp); | |
50c74957 | 660 | } |
661 | ||
662 | int main(int argc, char *argv[]) | |
663 | { | |
664 | const char *kfname = "keyring.pub"; | |
665 | int i; | |
666 | unsigned f = 0; | |
9f90c1f6 MW |
667 | char buf[32]; |
668 | static octet zero[CHACHA_NONCESZ]; | |
50c74957 | 669 | |
670 | #define f_bogus 1u | |
671 | ||
672 | ego(argv[0]); | |
673 | for (;;) { | |
674 | static const struct option opt[] = { | |
675 | { "help", 0, 0, 'h' }, | |
676 | { "version", 0, 0, 'v' }, | |
677 | { "usage", 0, 0, 'u' }, | |
a8ce36a6 | 678 | { "delimiter", OPTF_ARGREQ, 0, 'd' }, |
50c74957 | 679 | { "keyring", OPTF_ARGREQ, 0, 'k' }, |
680 | { 0, 0, 0, 0 } | |
681 | }; | |
a8ce36a6 | 682 | if ((i = mdwopt(argc, argv, "hvud:k:", opt, 0, 0, 0)) < 0) break; |
50c74957 | 683 | switch (i) { |
6dbded74 MW |
684 | case 'h': help(stdout); exit(0); |
685 | case 'v': version(stdout); exit(0); | |
686 | case 'u': usage(stdout); exit(0); | |
a8ce36a6 MW |
687 | case 'd': |
688 | if (!optarg[0] || optarg[1]) | |
689 | die(1, "delimiter must be a single character"); | |
690 | delim = optarg; | |
691 | break; | |
6dbded74 MW |
692 | case 'k': kfname = optarg; break; |
693 | default: f |= f_bogus; break; | |
50c74957 | 694 | } |
695 | } | |
6dbded74 MW |
696 | if (f & f_bogus) { usage(stderr); exit(1); } |
697 | ||
50c74957 | 698 | rand_noisesrc(RAND_GLOBAL, &noise_source); |
9f90c1f6 | 699 | rand_seed(RAND_GLOBAL, 256); |
50c74957 | 700 | rand_get(RAND_GLOBAL, buf, sizeof(buf)); |
9f90c1f6 | 701 | rng = chacha20_rand(buf, sizeof(buf), zero); |
50c74957 | 702 | sel_init(&sel); |
703 | if (key_open(&keys, kfname, KOPEN_READ, key_moan, 0)) | |
704 | die(1, "couldn't open `%s': %s", kfname, strerror(errno)); | |
6dbded74 MW |
705 | for (i = optind; i < argc; i++) parse(argv[i]); |
706 | if (npeer != 2) die(1, "need two peers"); | |
c9cb7c0c MW |
707 | for (;;) { |
708 | if (sel_select(&sel) && errno != EINTR) | |
709 | die(1, "select failed: %s", strerror(errno)); | |
710 | } | |
50c74957 | 711 | |
712 | #undef f_bogus | |
713 | } | |
714 | ||
715 | /*----- That's all, folks -------------------------------------------------*/ |