/*
- conf.c -- configuration code
- Copyright (C) 1998 Robert van der Meulen
- 1998-2002 Ivo Timmermans <ivo@o2w.nl>
- 2000-2002 Guus Sliepen <guus@sliepen.eu.org>
- 2000 Cris van Pelt <tribbel@arise.dhs.org>
+ econf.c -- configuration code
+ Copyright (C) 2018 Guus Sliepen <guus@meshlink.io>
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
- You should have received a copy of the GNU General Public License
- along with this program; if not, write to the Free Software
- Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
-
- $Id: conf.c,v 1.9.4.61 2002/09/15 12:26:24 guus Exp $
+ You should have received a copy of the GNU General Public License along
+ with this program; if not, write to the Free Software Foundation, Inc.,
+ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
*/
-#include "config.h"
-
-#include <ctype.h>
-#include <errno.h>
-#include <netdb.h>
-#include <stdio.h>
-#include <stdlib.h>
-#include <string.h>
-#include <syslog.h>
-#include <sys/stat.h>
+#include "system.h"
+#include <assert.h>
#include <sys/types.h>
-#include <unistd.h>
-#include <syslog.h>
-#include <string.h>
-
-#include <xalloc.h>
-#include <utils.h> /* for cp */
-#include <avl_tree.h>
+#include <utime.h>
#include "conf.h"
-#include "netutl.h" /* for str2address */
+#include "crypto.h"
+#include "logger.h"
+#include "meshlink_internal.h"
+#include "xalloc.h"
+#include "packmsg.h"
+
+/// Generate a path to the main configuration file.
+static void make_main_path(meshlink_handle_t *mesh, const char *conf_subdir, char *path, size_t len) {
+ snprintf(path, len, "%s" SLASH "%s" SLASH "meshlink.conf", mesh->confbase, conf_subdir);
+}
-#include "system.h"
+/// Generate a path to a host configuration file.
+static void make_host_path(meshlink_handle_t *mesh, const char *conf_subdir, const char *name, char *path, size_t len) {
+ snprintf(path, len, "%s" SLASH "%s" SLASH "hosts" SLASH "%s", mesh->confbase, conf_subdir, name);
+}
-avl_tree_t *config_tree;
+/// Generate a path to an unused invitation file.
+static void make_invitation_path(meshlink_handle_t *mesh, const char *conf_subdir, const char *name, char *path, size_t len) {
+ snprintf(path, len, "%s" SLASH "%s" SLASH "invitations" SLASH "%s", mesh->confbase, conf_subdir, name);
+}
-int debug_lvl = 0;
-int pingtimeout = 0; /* seconds before timeout */
-char *confbase = NULL; /* directory in which all config files are */
-char *netname = NULL; /* name of the vpn network */
+/// Generate a path to a used invitation file.
+static void make_used_invitation_path(meshlink_handle_t *mesh, const char *conf_subdir, const char *name, char *path, size_t len) {
+ snprintf(path, len, "%s" SLASH "%s" SLASH "invitations" SLASH "%s.used", mesh->confbase, conf_subdir, name);
+}
-int config_compare(config_t *a, config_t *b)
-{
- int result;
+/// Remove a directory recursively
+static void deltree(const char *dirname) {
+ DIR *d = opendir(dirname);
- result = strcasecmp(a->variable, b->variable);
+ if(d) {
+ struct dirent *ent;
- if(result)
- return result;
+ while((ent = readdir(d))) {
+ if(ent->d_name[0] == '.') {
+ continue;
+ }
- result = a->line - b->line;
+ char filename[PATH_MAX];
+ snprintf(filename, sizeof(filename), "%s" SLASH "%s", dirname, ent->d_name);
- if(result)
- return result;
- else
- return strcmp(a->file, b->file);
-}
+ if(unlink(filename)) {
+ deltree(filename);
+ }
+ }
-void init_configuration(avl_tree_t ** config_tree)
-{
- cp();
+ closedir(d);
+ }
- *config_tree = avl_alloc_tree((avl_compare_t) config_compare, (avl_action_t) free_config);
+ rmdir(dirname);
}
-void exit_configuration(avl_tree_t ** config_tree)
-{
- cp();
+static bool sync_path(const char *pathname) {
+ int fd = open(pathname, O_RDONLY);
- avl_delete_tree(*config_tree);
- *config_tree = NULL;
-}
+ if(fd < 0) {
+ logger(NULL, MESHLINK_ERROR, "Failed to open %s: %s\n", pathname, strerror(errno));
+ return false;
+ }
-config_t *new_config(void)
-{
- cp();
+ if(fsync(fd)) {
+ logger(NULL, MESHLINK_ERROR, "Failed to sync %s: %s\n", pathname, strerror(errno));
+ close(fd);
+ return false;
+ }
- return (config_t *) xmalloc_and_zero(sizeof(config_t));
+ if(close(fd)) {
+ logger(NULL, MESHLINK_ERROR, "Failed to close %s: %s\n", pathname, strerror(errno));
+ close(fd);
+ return false;
+ }
+
+ return true;
}
-void free_config(config_t *cfg)
-{
- cp();
+/// Try decrypting the main configuration file from the given sub-directory.
+static bool main_config_decrypt(meshlink_handle_t *mesh, const char *conf_subdir) {
+ if(!mesh->config_key && !mesh->confbase && !conf_subdir) {
+ return false;
+ }
- if(cfg->variable)
- free(cfg->variable);
+ config_t config;
- if(cfg->value)
- free(cfg->value);
+ if(!main_config_read(mesh, conf_subdir, &config, mesh->config_key)) {
+ logger(mesh, MESHLINK_ERROR, "Could not read main configuration file");
+ return false;
+ }
- if(cfg->file)
- free(cfg->file);
+ packmsg_input_t in = {config.buf, config.len};
- free(cfg);
+ uint32_t version = packmsg_get_uint32(&in);
+ config_free(&config);
+
+ return version == MESHLINK_CONFIG_VERSION;
}
-void config_add(avl_tree_t *config_tree, config_t *cfg)
-{
- cp();
+/// Create a fresh configuration directory
+bool config_init(meshlink_handle_t *mesh, const char *conf_subdir) {
+ if(!mesh->confbase) {
+ return true;
+ }
+
+ if(!conf_subdir) {
+ return false;
+ }
- avl_insert(config_tree, cfg);
-}
+ if(mkdir(mesh->confbase, 0700) && errno != EEXIST) {
+ logger(mesh, MESHLINK_DEBUG, "Could not create directory %s: %s\n", mesh->confbase, strerror(errno));
+ return false;
+ }
+
+ char path[PATH_MAX];
-config_t *lookup_config(avl_tree_t *config_tree, char *variable)
-{
- config_t cfg, *found;
+ // Create "current" sub-directory in the confbase
+ snprintf(path, sizeof(path), "%s" SLASH "%s", mesh->confbase, conf_subdir);
+ deltree(path);
- cp();
+ if(mkdir(path, 0700)) {
+ logger(mesh, MESHLINK_DEBUG, "Could not create directory %s: %s\n", path, strerror(errno));
+ return false;
+ }
- cfg.variable = variable;
- cfg.file = "";
- cfg.line = 0;
+ make_host_path(mesh, conf_subdir, "", path, sizeof(path));
- found = avl_search_closest_greater(config_tree, &cfg);
+ if(mkdir(path, 0700)) {
+ logger(mesh, MESHLINK_DEBUG, "Could not create directory %s: %s\n", path, strerror(errno));
+ return false;
+ }
- if(!found)
- return NULL;
+ make_invitation_path(mesh, conf_subdir, "", path, sizeof(path));
- if(strcasecmp(found->variable, variable))
- return NULL;
+ if(mkdir(path, 0700)) {
+ logger(mesh, MESHLINK_DEBUG, "Could not create directory %s: %s\n", path, strerror(errno));
+ return false;
+ }
- return found;
+ return true;
}
-config_t *lookup_config_next(avl_tree_t *config_tree, config_t *cfg)
-{
- avl_node_t *node;
- config_t *found;
+/// Wipe an existing configuration directory
+bool config_destroy(const char *confbase, const char *conf_subdir) {
+ if(!confbase && !conf_subdir) {
+ return false;
+ }
- cp();
+ struct stat st;
- node = avl_search_node(config_tree, cfg);
+ char path[PATH_MAX];
- if(node) {
- if(node->next) {
- found = (config_t *) node->next->data;
+ // Check the presence of configuration base sub directory.
+ snprintf(path, sizeof(path), "%s" SLASH "%s", confbase, conf_subdir);
- if(!strcasecmp(found->variable, cfg->variable))
- return found;
+ if(stat(path, &st)) {
+ if(errno == ENOENT) {
+ return true;
+ } else {
+ logger(NULL, MESHLINK_ERROR, "Cannot stat %s: %s\n", path, strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ return false;
}
}
- return NULL;
+ // Remove meshlink.conf
+ snprintf(path, sizeof(path), "%s" SLASH "%s" SLASH "meshlink.conf", confbase, conf_subdir);
+
+ if(unlink(path)) {
+ if(errno != ENOENT) {
+ logger(NULL, MESHLINK_ERROR, "Cannot delete %s: %s\n", path, strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ return false;
+ }
+ }
+
+ snprintf(path, sizeof(path), "%s" SLASH "%s", confbase, conf_subdir);
+ deltree(path);
+ return true;
}
-int get_config_bool(config_t *cfg, int *result)
-{
- cp();
+static bool copytree(const char *src_dir_name, const void *src_key, const char *dst_dir_name, const void *dst_key) {
+ if(!src_dir_name || !dst_dir_name) {
+ return false;
+ }
+
+ char src_filename[PATH_MAX];
+ char dst_filename[PATH_MAX];
+ struct dirent *ent;
- if(!cfg)
- return 0;
+ DIR *src_dir = opendir(src_dir_name);
- if(!strcasecmp(cfg->value, "yes")) {
- *result = 1;
- return 1;
- } else if(!strcasecmp(cfg->value, "no")) {
- *result = 0;
- return 1;
+ if(!src_dir) {
+ logger(NULL, MESHLINK_ERROR, "Could not open directory file %s\n", src_dir_name);
+ return false;
}
- syslog(LOG_ERR, _("\"yes\" or \"no\" expected for configuration variable %s in %s line %d"),
- cfg->variable, cfg->file, cfg->line);
+ // Delete if already exists and create a new destination directory
+ deltree(dst_dir_name);
- return 0;
-}
+ if(mkdir(dst_dir_name, 0700)) {
+ logger(NULL, MESHLINK_ERROR, "Could not create directory %s\n", dst_filename);
+ return false;
+ }
-int get_config_int(config_t *cfg, int *result)
-{
- cp();
+ while((ent = readdir(src_dir))) {
+ if(ent->d_name[0] == '.') {
+ continue;
+ }
- if(!cfg)
- return 0;
+ snprintf(dst_filename, sizeof(dst_filename), "%s" SLASH "%s", dst_dir_name, ent->d_name);
+ snprintf(src_filename, sizeof(src_filename), "%s" SLASH "%s", src_dir_name, ent->d_name);
+
+ if(ent->d_type == DT_DIR) {
+ if(!copytree(src_filename, src_key, dst_filename, dst_key)) {
+ logger(NULL, MESHLINK_ERROR, "Copying %s to %s failed\n", src_filename, dst_filename);
+ return false;
+ }
- if(sscanf(cfg->value, "%d", result) == 1)
- return 1;
+ if(!sync_path(dst_filename)) {
+ return false;
+ }
+ } else if(ent->d_type == DT_REG) {
+ struct stat st;
+ config_t config;
- syslog(LOG_ERR, _("Integer expected for configuration variable %s in %s line %d"),
- cfg->variable, cfg->file, cfg->line);
+ if(stat(src_filename, &st)) {
+ logger(NULL, MESHLINK_ERROR, "Could not stat file `%s': %s\n", src_filename, strerror(errno));
+ return false;
+ }
- return 0;
-}
+ FILE *f = fopen(src_filename, "r");
-int get_config_string(config_t *cfg, char **result)
-{
- cp();
+ if(!f) {
+ logger(NULL, MESHLINK_ERROR, "Failed to open `%s': %s\n", src_filename, strerror(errno));
+ return false;
+ }
- if(!cfg)
- return 0;
+ if(!config_read_file(NULL, f, &config, src_key)) {
+ logger(NULL, MESHLINK_ERROR, "Failed to read `%s': %s\n", src_filename, strerror(errno));
+ fclose(f);
+ return false;
+ }
- *result = xstrdup(cfg->value);
+ if(fclose(f)) {
+ logger(NULL, MESHLINK_ERROR, "Failed to close `%s': %s\n", src_filename, strerror(errno));
+ config_free(&config);
+ return false;
+ }
- return 1;
-}
+ f = fopen(dst_filename, "w");
-int get_config_address(config_t *cfg, struct addrinfo **result)
-{
- struct addrinfo *ai;
+ if(!f) {
+ logger(NULL, MESHLINK_ERROR, "Failed to open `%s': %s", dst_filename, strerror(errno));
+ config_free(&config);
+ return false;
+ }
- cp();
+ if(!config_write_file(NULL, f, &config, dst_key)) {
+ logger(NULL, MESHLINK_ERROR, "Failed to write `%s': %s", dst_filename, strerror(errno));
+ config_free(&config);
+ fclose(f);
+ return false;
+ }
- if(!cfg)
- return 0;
+ if(fclose(f)) {
+ logger(NULL, MESHLINK_ERROR, "Failed to close `%s': %s", dst_filename, strerror(errno));
+ config_free(&config);
+ return false;
+ }
- ai = str2addrinfo(cfg->value, NULL, 0);
+ config_free(&config);
- if(ai) {
- *result = ai;
- return 1;
+ struct utimbuf times;
+ times.modtime = st.st_mtime;
+ times.actime = st.st_atime;
+
+ if(utime(dst_filename, ×)) {
+ logger(NULL, MESHLINK_ERROR, "Failed to utime `%s': %s", dst_filename, strerror(errno));
+ return false;
+ }
+ }
}
- syslog(LOG_ERR, _("Hostname or IP address expected for configuration variable %s in %s line %d"),
- cfg->variable, cfg->file, cfg->line);
+ closedir(src_dir);
+ return true;
+}
+
+bool config_copy(meshlink_handle_t *mesh, const char *src_dir_name, const void *src_key, const char *dst_dir_name, const void *dst_key) {
+ char src_filename[PATH_MAX];
+ char dst_filename[PATH_MAX];
+
+ snprintf(dst_filename, sizeof(dst_filename), "%s" SLASH "%s", mesh->confbase, dst_dir_name);
+ snprintf(src_filename, sizeof(src_filename), "%s" SLASH "%s", mesh->confbase, src_dir_name);
- return 0;
+ return copytree(src_filename, src_key, dst_filename, dst_key);
}
-int get_config_subnet(config_t *cfg, subnet_t ** result)
-{
- subnet_t *subnet;
+/// Check the presence of the main configuration file.
+bool main_config_exists(meshlink_handle_t *mesh, const char *conf_subdir) {
+ if(!mesh->confbase && !conf_subdir) {
+ return false;
+ }
- cp();
+ char path[PATH_MAX];
+ make_main_path(mesh, conf_subdir, path, sizeof(path));
+ return access(path, F_OK) == 0;
+}
- if(!cfg)
- return 0;
+bool config_rename(meshlink_handle_t *mesh, const char *old_conf_subdir, const char *new_conf_subdir) {
+ if(!mesh->confbase && !old_conf_subdir && !new_conf_subdir) {
+ return false;
+ }
- subnet = str2net(cfg->value);
+ char old_path[PATH_MAX];
+ char new_path[PATH_MAX];
- if(!subnet) {
- syslog(LOG_ERR, _("Subnet expected for configuration variable %s in %s line %d"),
- cfg->variable, cfg->file, cfg->line);
- return 0;
+ snprintf(old_path, sizeof(old_path), "%s" SLASH "%s", mesh->confbase, old_conf_subdir);
+ snprintf(new_path, sizeof(new_path), "%s" SLASH "%s", mesh->confbase, new_conf_subdir);
+
+ return rename(old_path, new_path) == 0;
+}
+
+bool meshlink_confbase_exists(meshlink_handle_t *mesh) {
+ if(!mesh->confbase) {
+ return false;
}
- /* Teach newbies what subnets are... */
+ bool confbase_exists = false;
+ bool confbase_decryptable = false;
- if(((subnet->type == SUBNET_IPV4)
- && maskcheck(&subnet->net.ipv4.address, subnet->net.ipv4.prefixlength, sizeof(ipv4_t)))
- || ((subnet->type == SUBNET_IPV6)
- && maskcheck(&subnet->net.ipv6.address, subnet->net.ipv6.prefixlength, sizeof(ipv6_t)))) {
- syslog(LOG_ERR, _ ("Network address and prefix length do not match for configuration variable %s in %s line %d"),
- cfg->variable, cfg->file, cfg->line);
- free(subnet);
- return 0;
+ if(main_config_exists(mesh, "current")) {
+ confbase_exists = true;
+
+ if(mesh->config_key && main_config_decrypt(mesh, "current")) {
+ confbase_decryptable = true;
+ }
}
- *result = subnet;
+ if(mesh->config_key && !confbase_decryptable && main_config_exists(mesh, "new")) {
+ confbase_exists = true;
- return 1;
-}
+ if(main_config_decrypt(mesh, "new")) {
+ if(!config_destroy(mesh->confbase, "current")) {
+ return false;
+ }
-/*
- Read exactly one line and strip the trailing newline if any. If the
- file was on EOF, return NULL. Otherwise, return all the data in a
- dynamically allocated buffer.
-
- If line is non-NULL, it will be used as an initial buffer, to avoid
- unnecessary mallocing each time this function is called. If buf is
- given, and buf needs to be expanded, the var pointed to by buflen
- will be increased.
-*/
-char *readline(FILE * fp, char **buf, size_t *buflen)
-{
- char *newline = NULL;
- char *p;
- char *line; /* The array that contains everything that has been read so far */
- char *idx; /* Read into this pointer, which points to an offset within line */
- size_t size, newsize; /* The size of the current array pointed to by line */
- size_t maxlen; /* Maximum number of characters that may be read with fgets. This is newsize - oldsize. */
-
- if(feof(fp))
- return NULL;
-
- if(buf && buflen) {
- size = *buflen;
- line = *buf;
- } else {
- size = 100;
- line = xmalloc(size);
- }
-
- maxlen = size;
- idx = line;
- *idx = 0;
-
- for(;;) {
- errno = 0;
- p = fgets(idx, maxlen, fp);
-
- if(!p) { /* EOF or error */
- if(feof(fp))
- break;
-
- /* otherwise: error; let the calling function print an error message if applicable */
- free(line);
- return NULL;
+ if(!config_rename(mesh, "new", "current")) {
+ return false;
+ }
+
+ confbase_decryptable = true;
}
+ }
- newline = strchr(p, '\n');
+ if(mesh->config_key && !confbase_decryptable && main_config_exists(mesh, "old")) {
+ confbase_exists = true;
- if(!newline) { /* We haven't yet read everything to the end of the line */
- newsize = size << 1;
- line = xrealloc(line, newsize);
- idx = &line[size - 1];
- maxlen = newsize - size + 1;
- size = newsize;
- } else {
- *newline = '\0'; /* kill newline */
- break; /* yay */
+ if(main_config_decrypt(mesh, "old")) {
+ if(!config_destroy(mesh->confbase, "current")) {
+ return false;
+ }
+
+ if(!config_rename(mesh, "old", "current")) {
+ return false;
+ }
+
+ confbase_decryptable = true;
}
}
- if(buf && buflen) {
- *buflen = size;
- *buf = line;
+ // Cleanup if current is existing with old and new
+ if(confbase_exists && confbase_decryptable) {
+ config_destroy(mesh->confbase, "old");
+ config_destroy(mesh->confbase, "new");
}
- return line;
+ return confbase_exists;
}
-/*
- Parse a configuration file and put the results in the configuration tree
- starting at *base.
-*/
-int read_config_file(avl_tree_t *config_tree, const char *fname)
-{
- int err = -2; /* Parse error */
- FILE *fp;
- char *buffer, *line;
- char *variable, *value;
- int lineno = 0, ignore = 0;
- config_t *cfg;
- size_t bufsize;
+/// Lock the main configuration file.
+bool main_config_lock(meshlink_handle_t *mesh) {
+ if(!mesh->confbase) {
+ return true;
+ }
- cp();
+ char path[PATH_MAX];
+ make_main_path(mesh, "current", path, sizeof(path));
- fp = fopen(fname, "r");
+ mesh->conffile = fopen(path, "r");
- if(!fp) {
- syslog(LOG_ERR, _("Cannot open config file %s: %s"), fname,
- strerror(errno));
- return -3;
+ if(!mesh->conffile) {
+ logger(NULL, MESHLINK_ERROR, "Cannot not open %s: %s\n", path, strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ return false;
}
- bufsize = 100;
- buffer = xmalloc(bufsize);
+#ifdef FD_CLOEXEC
+ fcntl(fileno(mesh->conffile), F_SETFD, FD_CLOEXEC);
+#endif
- for(;;) {
- line = readline(fp, &buffer, &bufsize);
+#ifdef HAVE_MINGW
+ // TODO: use _locking()?
+#else
- if(!line) {
- err = -1;
- break;
- }
+ if(flock(fileno(mesh->conffile), LOCK_EX | LOCK_NB) != 0) {
+ logger(NULL, MESHLINK_ERROR, "Cannot lock %s: %s\n", path, strerror(errno));
+ fclose(mesh->conffile);
+ mesh->conffile = NULL;
+ meshlink_errno = MESHLINK_EBUSY;
+ return false;
+ }
- if(feof(fp)) {
- err = 0;
- break;
- }
+#endif
+
+ return true;
+}
- lineno++;
+/// Unlock the main configuration file.
+void main_config_unlock(meshlink_handle_t *mesh) {
+ if(mesh->conffile) {
+ fclose(mesh->conffile);
+ mesh->conffile = NULL;
+ }
+}
- variable = strtok(line, "\t =");
+/// Read a configuration file from a FILE handle.
+bool config_read_file(meshlink_handle_t *mesh, FILE *f, config_t *config, const void *key) {
+ long len;
- if(!variable)
- continue; /* no tokens on this line */
+ if(fseek(f, 0, SEEK_END) || !(len = ftell(f)) || fseek(f, 0, SEEK_SET)) {
+ logger(mesh, MESHLINK_ERROR, "Cannot get config file size: %s\n", strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ fclose(f);
+ return false;
+ }
- if(variable[0] == '#')
- continue; /* comment: ignore */
+ uint8_t *buf = xmalloc(len);
- if(!strcmp(variable, "-----BEGIN"))
- ignore = 1;
+ if(fread(buf, len, 1, f) != 1) {
+ logger(mesh, MESHLINK_ERROR, "Cannot read config file: %s\n", strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ fclose(f);
+ return false;
+ }
- if(!ignore) {
- value = strtok(NULL, "\t\n\r =");
+ if(key) {
+ uint8_t *decrypted = xmalloc(len);
+ size_t decrypted_len = len;
+ chacha_poly1305_ctx_t *ctx = chacha_poly1305_init();
+ chacha_poly1305_set_key(ctx, key);
+
+ if(len > 12 && chacha_poly1305_decrypt_iv96(ctx, buf, buf + 12, len - 12, decrypted, &decrypted_len)) {
+ chacha_poly1305_exit(ctx);
+ free(buf);
+ config->buf = decrypted;
+ config->len = decrypted_len;
+ return true;
+ } else {
+ logger(mesh, MESHLINK_ERROR, "Cannot decrypt config file\n");
+ meshlink_errno = MESHLINK_ESTORAGE;
+ chacha_poly1305_exit(ctx);
+ free(decrypted);
+ free(buf);
+ return false;
+ }
+ }
- if(!value || value[0] == '#') {
- syslog(LOG_ERR, _("No value for variable `%s' on line %d while reading config file %s"),
- variable, lineno, fname);
- break;
- }
+ config->buf = buf;
+ config->len = len;
- cfg = new_config();
- cfg->variable = xstrdup(variable);
- cfg->value = xstrdup(value);
- cfg->file = xstrdup(fname);
- cfg->line = lineno;
+ return true;
+}
- config_add(config_tree, cfg);
+/// Write a configuration file to a FILE handle.
+bool config_write_file(meshlink_handle_t *mesh, FILE *f, const config_t *config, const void *key) {
+ if(key) {
+ uint8_t buf[config->len + 16];
+ size_t len = sizeof(buf);
+ uint8_t seqbuf[12];
+ randomize(&seqbuf, sizeof(seqbuf));
+ chacha_poly1305_ctx_t *ctx = chacha_poly1305_init();
+ chacha_poly1305_set_key(ctx, key);
+ bool success = false;
+
+ if(chacha_poly1305_encrypt_iv96(ctx, seqbuf, config->buf, config->len, buf, &len)) {
+ success = fwrite(seqbuf, sizeof(seqbuf), 1, f) == 1 && fwrite(buf, len, 1, f) == 1;
+ } else {
+ logger(mesh, MESHLINK_ERROR, "Cannot encrypt config file\n");
+ meshlink_errno = MESHLINK_ESTORAGE;
}
- if(!strcmp(variable, "-----END"))
- ignore = 0;
+ chacha_poly1305_exit(ctx);
+ return success;
+ }
+
+ if(fwrite(config->buf, config->len, 1, f) != 1) {
+ logger(mesh, MESHLINK_ERROR, "Cannot write config file: %s", strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ return false;
+ }
+
+ if(fsync(fileno(f))) {
+ logger(mesh, MESHLINK_ERROR, "Failed to sync file: %s\n", strerror(errno));
+ return false;
+ }
+
+ return true;
+}
+
+/// Free resources of a loaded configuration file.
+void config_free(config_t *config) {
+ free((uint8_t *)config->buf);
+ config->buf = NULL;
+ config->len = 0;
+}
+
+/// Check the presence of a host configuration file.
+bool config_exists(meshlink_handle_t *mesh, const char *conf_subdir, const char *name) {
+ if(!mesh->confbase && !conf_subdir) {
+ return false;
}
- free(buffer);
- fclose(fp);
+ char path[PATH_MAX];
+ make_host_path(mesh, conf_subdir, name, path, sizeof(path));
- return err;
+ return access(path, F_OK) == 0;
}
-int read_server_config()
-{
- char *fname;
- int x;
+/// Read a host configuration file.
+bool config_read(meshlink_handle_t *mesh, const char *conf_subdir, const char *name, config_t *config, void *key) {
+ if(!mesh->confbase && !conf_subdir) {
+ return false;
+ }
+
+ char path[PATH_MAX];
+ make_host_path(mesh, conf_subdir, name, path, sizeof(path));
- cp();
+ FILE *f = fopen(path, "r");
- asprintf(&fname, "%s/tinc.conf", confbase);
- x = read_config_file(config_tree, fname);
+ if(!f) {
+ logger(mesh, MESHLINK_ERROR, "Failed to open `%s': %s", path, strerror(errno));
+ return false;
+ }
- if(x == -1) { /* System error: complain */
- syslog(LOG_ERR, _("Failed to read `%s': %s"), fname, strerror(errno));
+ if(!config_read_file(mesh, f, config, key)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to read `%s': %s", path, strerror(errno));
+ fclose(f);
+ return false;
}
- free(fname);
+ fclose(f);
- return x;
+ return true;
}
-int isadir(const char *f)
-{
- struct stat s;
+bool config_scan_all(meshlink_handle_t *mesh, const char *conf_subdir, const char *conf_type, config_scan_action_t action, void *arg) {
+ if(!mesh->confbase && !conf_subdir && !conf_type) {
+ return false;
+ }
- if(stat(f, &s) < 0)
- return 0;
- else
- return S_ISDIR(s.st_mode);
+ DIR *dir;
+ struct dirent *ent;
+ char dname[PATH_MAX];
+ snprintf(dname, sizeof(dname), "%s" SLASH "%s" SLASH "%s", mesh->confbase, conf_subdir, conf_type);
+
+ dir = opendir(dname);
+
+ if(!dir) {
+ logger(mesh, MESHLINK_ERROR, "Could not open %s: %s", dname, strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ return false;
+ }
+
+ while((ent = readdir(dir))) {
+ if(ent->d_name[0] == '.') {
+ continue;
+ }
+
+ if(!action(mesh, ent->d_name, arg)) {
+ closedir(dir);
+ return false;
+ }
+ }
+
+ closedir(dir);
+ return true;
}
-int is_safe_path(const char *file)
-{
- char *p;
- const char *f;
- char x;
- struct stat s;
- char l[MAXBUFSIZE];
+/// Write a host configuration file.
+bool config_write(meshlink_handle_t *mesh, const char *conf_subdir, const char *name, const config_t *config, void *key) {
+ if(!mesh->confbase && !conf_subdir && !name) {
+ return true;
+ }
+
+ char path[PATH_MAX];
+ make_host_path(mesh, conf_subdir, name, path, sizeof(path));
- if(*file != '/') {
- syslog(LOG_ERR, _("`%s' is not an absolute path"), file);
- return 0;
+ FILE *f = fopen(path, "w");
+
+ if(!f) {
+ logger(mesh, MESHLINK_ERROR, "Failed to open `%s': %s", path, strerror(errno));
+ return false;
}
- p = strrchr(file, '/');
+ if(!config_write_file(mesh, f, config, key)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to write `%s': %s", path, strerror(errno));
+ fclose(f);
+ return false;
+ }
- if(p == file) /* It's in the root */
- p++;
+ if(fclose(f)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to close `%s': %s", path, strerror(errno));
+ return false;
+ }
- x = *p;
- *p = '\0';
+ return true;
+}
- f = file;
+/// Read the main configuration file.
+bool main_config_read(meshlink_handle_t *mesh, const char *conf_subdir, config_t *config, void *key) {
+ if(!mesh->confbase && !conf_subdir) {
+ return false;
+ }
-check1:
- if(lstat(f, &s) < 0) {
- syslog(LOG_ERR, _("Couldn't stat `%s': %s"), f, strerror(errno));
- return 0;
+ char path[PATH_MAX];
+ make_main_path(mesh, conf_subdir, path, sizeof(path));
+
+ FILE *f = fopen(path, "r");
+
+ if(!f) {
+ logger(mesh, MESHLINK_ERROR, "Failed to open `%s': %s", path, strerror(errno));
+ return false;
}
- if(s.st_uid != geteuid()) {
- syslog(LOG_ERR, _("`%s' is owned by UID %d instead of %d"),
- f, s.st_uid, geteuid());
- return 0;
+ if(!config_read_file(mesh, f, config, key)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to read `%s': %s", path, strerror(errno));
+ fclose(f);
+ return false;
}
- if(S_ISLNK(s.st_mode)) {
- syslog(LOG_WARNING, _("Warning: `%s' is a symlink"), f);
+ fclose(f);
- if(readlink(f, l, MAXBUFSIZE) < 0) {
- syslog(LOG_ERR, _("Unable to read symbolic link `%s': %s"), f,
- strerror(errno));
- return 0;
- }
+ return true;
+}
- f = l;
- goto check1;
+/// Write the main configuration file.
+bool main_config_write(meshlink_handle_t *mesh, const char *conf_subdir, const config_t *config, void *key) {
+ if(!mesh->confbase && !conf_subdir) {
+ return true;
}
- *p = x;
- f = file;
+ char path[PATH_MAX];
+ make_main_path(mesh, conf_subdir, path, sizeof(path));
-check2:
- if(lstat(f, &s) < 0 && errno != ENOENT) {
- syslog(LOG_ERR, _("Couldn't stat `%s': %s"), f, strerror(errno));
- return 0;
+ FILE *f = fopen(path, "w");
+
+ if(!f) {
+ logger(mesh, MESHLINK_ERROR, "Failed to open `%s': %s", path, strerror(errno));
+ return false;
}
- if(errno == ENOENT)
- return 1;
+ if(!config_write_file(mesh, f, config, key)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to write `%s': %s", path, strerror(errno));
+ fclose(f);
+ return false;
+ }
- if(s.st_uid != geteuid()) {
- syslog(LOG_ERR, _("`%s' is owned by UID %d instead of %d"),
- f, s.st_uid, geteuid());
- return 0;
+ if(fclose(f)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to close `%s': %s", path, strerror(errno));
+ return false;
}
- if(S_ISLNK(s.st_mode)) {
- syslog(LOG_WARNING, _("Warning: `%s' is a symlink"), f);
+ return true;
+}
+
+/// Read an invitation file from the confbase sub-directory, and immediately delete it.
+bool invitation_read(meshlink_handle_t *mesh, const char *conf_subdir, const char *name, config_t *config, void *key) {
+ if(!mesh->confbase && !conf_subdir) {
+ return false;
+ }
- if(readlink(f, l, MAXBUFSIZE) < 0) {
- syslog(LOG_ERR, _("Unable to read symbolic link `%s': %s"), f,
- strerror(errno));
- return 0;
+ char path[PATH_MAX];
+ char used_path[PATH_MAX];
+ make_invitation_path(mesh, conf_subdir, name, path, sizeof(path));
+ make_used_invitation_path(mesh, conf_subdir, name, used_path, sizeof(used_path));
+
+ // Atomically rename the invitation file
+ if(rename(path, used_path)) {
+ if(errno == ENOENT) {
+ logger(mesh, MESHLINK_ERROR, "Peer tried to use non-existing invitation %s\n", name);
+ } else {
+ logger(mesh, MESHLINK_ERROR, "Error trying to rename invitation %s\n", name);
}
- f = l;
- goto check2;
+ return false;
}
- if(s.st_mode & 0007) {
- /* Accessible by others */
- syslog(LOG_ERR, _("`%s' has unsecure permissions"), f);
- return 0;
+ FILE *f = fopen(used_path, "r");
+
+ if(!f) {
+ logger(mesh, MESHLINK_ERROR, "Failed to open `%s': %s", path, strerror(errno));
+ return false;
+ }
+
+ // Check the timestamp
+ struct stat st;
+
+ if(fstat(fileno(f), &st)) {
+ logger(mesh, MESHLINK_ERROR, "Could not stat invitation file %s\n", name);
+ fclose(f);
+ unlink(used_path);
+ return false;
+ }
+
+ if(mesh->loop.now.tv_sec > st.st_mtime + mesh->invitation_timeout) {
+ logger(mesh, MESHLINK_ERROR, "Peer tried to use an outdated invitation file %s\n", name);
+ fclose(f);
+ unlink(used_path);
+ return false;
+ }
+
+ if(!config_read_file(mesh, f, config, key)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to read `%s': %s", path, strerror(errno));
+ fclose(f);
+ unlink(used_path);
+ return false;
}
- return 1;
+ fclose(f);
+
+ unlink(used_path);
+ return true;
}
-FILE *ask_and_safe_open(const char *filename, const char *what,
- const char *mode)
-{
- FILE *r;
- char *directory;
- char *fn;
-
- /* Check stdin and stdout */
- if(!isatty(0) || !isatty(1)) {
- /* Argh, they are running us from a script or something. Write
- the files to the current directory and let them burn in hell
- for ever. */
- fn = xstrdup(filename);
- } else {
- /* Ask for a file and/or directory name. */
- fprintf(stdout, _("Please enter a file to save %s to [%s]: "),
- what, filename);
- fflush(stdout);
-
- fn = readline(stdin, NULL, NULL);
-
- if(!fn) {
- fprintf(stderr, _("Error while reading stdin: %s\n"),
- strerror(errno));
- return NULL;
- }
+/// Write an invitation file.
+bool invitation_write(meshlink_handle_t *mesh, const char *conf_subdir, const char *name, const config_t *config, void *key) {
+ if(!mesh->confbase && !conf_subdir) {
+ return false;
+ }
+
+ char path[PATH_MAX];
+ make_invitation_path(mesh, conf_subdir, name, path, sizeof(path));
+
+ FILE *f = fopen(path, "w");
+
+ if(!f) {
+ logger(mesh, MESHLINK_ERROR, "Failed to open `%s': %s", path, strerror(errno));
+ return false;
+ }
+
+ if(!config_write_file(mesh, f, config, key)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to write `%s': %s", path, strerror(errno));
+ fclose(f);
+ return false;
+ }
+
+ if(fclose(f)) {
+ logger(mesh, MESHLINK_ERROR, "Failed to close `%s': %s", path, strerror(errno));
+ return false;
+ }
- if(!strlen(fn))
- /* User just pressed enter. */
- fn = xstrdup(filename);
+ return true;
+}
+
+/// Purge old invitation files
+size_t invitation_purge_old(meshlink_handle_t *mesh, time_t deadline) {
+ if(!mesh->confbase) {
+ return true;
}
- if(!strchr(fn, '/') || fn[0] != '/') {
- /* The directory is a relative path or a filename. */
- char *p;
+ char path[PATH_MAX];
+ make_invitation_path(mesh, "current", "", path, sizeof(path));
+
+ DIR *dir = opendir(path);
- directory = get_current_dir_name();
- asprintf(&p, "%s/%s", directory, fn);
- free(fn);
- free(directory);
- fn = p;
+ if(!dir) {
+ logger(mesh, MESHLINK_DEBUG, "Could not read directory %s: %s\n", path, strerror(errno));
+ meshlink_errno = MESHLINK_ESTORAGE;
+ return 0;
}
- umask(0077); /* Disallow everything for group and other */
+ errno = 0;
+ size_t count = 0;
+ struct dirent *ent;
- /* Open it first to keep the inode busy */
+ while((ent = readdir(dir))) {
+ if(strlen(ent->d_name) != 24) {
+ continue;
+ }
- r = fopen(fn, mode);
+ char invname[PATH_MAX];
+ struct stat st;
- if(!r) {
- fprintf(stderr, _("Error opening file `%s': %s\n"),
- fn, strerror(errno));
- free(fn);
- return NULL;
+ if(snprintf(invname, sizeof(invname), "%s" SLASH "%s", path, ent->d_name) >= PATH_MAX) {
+ logger(mesh, MESHLINK_DEBUG, "Filename too long: %s" SLASH "%s", path, ent->d_name);
+ continue;
+ }
+
+ if(!stat(invname, &st)) {
+ if(mesh->invitation_key && deadline < st.st_mtime) {
+ count++;
+ } else {
+ unlink(invname);
+ }
+ } else {
+ logger(mesh, MESHLINK_DEBUG, "Could not stat %s: %s\n", invname, strerror(errno));
+ errno = 0;
+ }
}
- /* Then check the file for nasty attacks */
- if(!is_safe_path(fn)) { /* Do not permit any directories that are readable or writeable by other users. */
- fprintf(stderr, _("The file `%s' (or any of the leading directories) has unsafe permissions.\n"
- "I will not create or overwrite this file.\n"), fn);
- fclose(r);
- free(fn);
- return NULL;
+ if(errno) {
+ logger(mesh, MESHLINK_DEBUG, "Error while reading directory %s: %s\n", path, strerror(errno));
+ closedir(dir);
+ meshlink_errno = MESHLINK_ESTORAGE;
+ return 0;
}
- free(fn);
+ closedir(dir);
- return r;
+ return count;
}