}
set extra(outside) {}
+set privkey(inside) test-example/inside.privkeys/
+set privkey(outside) test-example/outside.privkeys/
+
+set initiator inside
+
+proc sitesconf_hook {l} { return $l }
+
+proc oldsecnet {site} {
+ upvar #0 oldsecnet($site) oldsecnet
+ expr {[info exists oldsecnet] && [set oldsecnet]}
+}
+
proc mkconf {location site} {
global tmp
global builddir
global ports
global extra
global netlinkfh
+ upvar #0 privkey($site) privkey
set pipefp $tmp/$site.netlink
foreach tr {t r} {
file delete $pipefp.$tr
"
close $fakeuh
set cfg "
+ hash sha1;
netlink userv-ipif {
name \"netlink\";
userv-path \"$fakeuf\";
}
append cfg ";
local-name \"test-example/$location/$site\";
- local-key rsa-private(\"$builddir/test-example/$site.key\");
"
+ switch -glob $privkey {
+ */ {
+ set sitesconf sites.conf
+ append cfg "
+ key-cache priv-cache({
+ privkeys \"$builddir/${privkey}priv.\";
+ });
+"
+ }
+ * {
+ set sitesconf sites-nonego.conf
+ append cfg "
+ local-key rsa-private(\"$builddir/$privkey\");
+"
+ }
+ }
+ set sitesconf $builddir/test-example/$sitesconf
+
append cfg $extra($site)
append cfg "
log logfile {
prefix \"$site\";
class \"debug\",\"info\",\"notice\",\"warning\",\"error\",\"security\",\"fatal\";
+ "
+ if {[oldsecnet $site]} { append cfg "
+ filename \"/dev/stderr\";
+ " }
+ append cfg "
};
"
append cfg {
transform eax-serpent { }, serpent256-cbc { };
}
- set f [open $builddir/test-example/sites.conf r]
+ set pubkeys $tmp/$site.pubkeys
+ file delete -force $pubkeys
+ exec cp -rl $builddir/test-example/pubkeys $pubkeys
+
+ set f [open $sitesconf r]
+ while {[gets $f l] >= 0} {
+ regsub {\"[^\"]*test-example/pubkeys/} $l "\"$pubkeys/" l
+ set l [sitesconf_hook $l]
+ append cfg $l "\n"
+ }
set sites [read $f]
close $f
append cfg $sites
append cfg {
sites map(site,all-sites);
}
+
return $cfg
}
global netlinkfh
global env
global pidmap
+ global readbuf
upvar #0 pids($site) pid
+ set readbuf($site) {}
set cf $tmp/$site.conf
set ch [open $cf w]
puts $ch [mkconf $location $site]
close $ch
- set argl [list $builddir/secnet -dvnc $cf]
+ set secnet $builddir/secnet
+ if {[oldsecnet $site]} {
+ set secnet $env(OLD_SECNET_DIR)/secnet
+ }
+ set argl [list $secnet -dvnc $cf]
set divertk SECNET_STEST_DIVERT_$site
puts -nonewline "spawn"
foreach k [array names env] {
switch -glob $k {
SECNET_STEST_DIVERT_* -
- SECNET_TEST_BUILDDIR { }
+ SECNET_TEST_BUILDDIR - OLD_SECNET_DIR { }
*SECNET* -
*PRELOAD* { puts -nonewline " $k=$env($k)" }
}
proc netlink-readable {location site} {
global ok
+ upvar #0 readbuf($site) buf
upvar #0 netlinkfh($site.r) fh
- read $fh; # empty the buffer
- switch -exact $site {
- inside {
- puts OK
- finish 0
+ while 1 {
+ set x [read $fh]
+ set h [hbytes raw2h $x]
+ if {![hbytes length $h]} return
+ append buf $h
+ #puts "READABLE $site buf=$buf"
+ while {[regexp {^((?:..)*?)c0(.*)$} $buf dummy now buf]} {
+ #puts "READABLE $site now=$now (buf=$buf)"
+ regsub -all {^((?:..)*?)dbdc} $now {\1c0} now
+ regsub -all {^((?:..)*?)dbdd} $now {\1db} now
+ puts "netlink-got-packet $location $site $now"
+ netlink-got-packet $location $site $now
+ }
+ }
+}
+
+proc netlink-got-packet {location site data} {
+ global initiator
+ if {![hbytes length $data]} return
+ switch -exact $site!$initiator {
+ inside!inside - outside!outside {
+ switch -glob $data {
+ 45000054ed9d4000fe0166d9ac12e802ac12e80900* {
+ puts "OK $data"
+ finish 0
+ }
+ * {
+ error "unexpected $site $data"
+ }
+ }
}
- outside {
- error "inside rx'd!"
+ default {
+ error "$site rx'd! (initiator $initiator)"
}
}
}
proc sendpkt {} {
global netlinkfh
+ global initiator
set p {
4500 0054 ed9d 4000 4001 24da ac12 e809
ac12 e802 0800 1de4 2d96 0001 f1d4 a05d
2425 2627 2829 2a2b 2c2d 2e2f 3031 3233
3435 3637
}
- puts -nonewline $netlinkfh(inside.t) \
+ puts -nonewline $netlinkfh($initiator.t) \
[hbytes h2raw c0[join $p ""]c0]
}
exit $estatus
}
+proc reap {} {
+ global pidmap
+ #puts stderr REAPING
+ foreach pid [array names pidmap] {
+ set got [wait -nohang $pid]
+ if {![llength $got]} continue
+ set info $pidmap($pid)
+ unset pidmap($pid)
+ puts stderr "reaped $info: $got"
+ finish 1
+ }
+}
+
+signal -restart trap SIGCHLD { after idle reap }
+
proc udp-proxy {} {
global socktmp udpsock
set u $socktmp/udp