OpenVPN
forward.c
Go to the documentation of this file.
1/*
2 * OpenVPN -- An application to securely tunnel IP networks
3 * over a single TCP/UDP port, with support for SSL/TLS-based
4 * session authentication and key exchange,
5 * packet encryption, packet authentication, and
6 * packet compression.
7 *
8 * Copyright (C) 2002-2026 OpenVPN Inc <sales@openvpn.net>
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License version 2
12 * as published by the Free Software Foundation.
13 *
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 * GNU General Public License for more details.
18 *
19 * You should have received a copy of the GNU General Public License along
20 * with this program; if not, see <https://www.gnu.org/licenses/>.
21 */
22
23#ifdef HAVE_CONFIG_H
24#include "config.h"
25#endif
26
27#include "syshead.h"
28
29#include "forward.h"
30#include "init.h"
31#include "push.h"
32#include "gremlin.h"
33#include "mss.h"
34#include "event.h"
35#include "occ.h"
36#include "otime.h"
37#include "ping.h"
38#include "ps.h"
39#include "dhcp.h"
40#include "common.h"
41#include "ssl_verify.h"
42#include "dco.h"
43#include "auth_token.h"
44#include "tun_afunix.h"
45
46#include "memdbg.h"
47
50
51/* show event wait debugging info */
52
53#ifndef ENABLE_SMALL
54
55static const char *
57{
58 struct buffer out = alloc_buf_gc(64, gc);
59
60 buf_printf(&out, "I/O WAIT %s|%s| %s", tun_stat(c->c1.tuntap, EVENT_READ, gc),
62 for (int i = 0; i < c->c1.link_sockets_num; i++)
63 {
64 buf_printf(&out, "\n %s|%s", socket_stat(c->c2.link_sockets[i], EVENT_READ, gc),
66 }
67 return BSTR(&out);
68}
69
70static void
72{
73 struct gc_arena gc = gc_new();
75 gc_free(&gc);
76}
77
78#endif
79
80static void
82{
83 msg(D_STREAM_ERRORS, "Fatal TLS error (check_tls_errors_co), restarting");
84 register_signal(c->sig, c->c2.tls_exit_signal, "tls-error"); /* SOFT-SIGUSR1 -- TLS error */
85}
86
87static void
89{
90 register_signal(c->sig, c->c2.tls_exit_signal, "tls-error"); /* SOFT-SIGUSR1 -- TLS error */
91}
92
93/*
94 * TLS errors are fatal in TCP mode.
95 * Also check for --tls-exit trigger.
96 */
97static inline void
99{
100 if (c->c2.tls_multi && c->c2.tls_exit_signal)
101 {
103 {
104 if (c->c2.tls_multi->n_soft_errors)
105 {
107 }
108 }
109 else
110 {
111 if (c->c2.tls_multi->n_hard_errors)
112 {
114 }
115 }
116 }
117}
118
119/*
120 * Set our wakeup to 0 seconds, so we will be rescheduled
121 * immediately.
122 */
123static inline void
125{
126 c->c2.timeval.tv_sec = 0; /* ZERO-TIMEOUT */
127 c->c2.timeval.tv_usec = 0;
128}
129
130static inline void
131context_reschedule_sec(struct context *c, time_t sec)
132{
133 if (sec < 0)
134 {
135 sec = 0;
136 }
137 if (sec < c->c2.timeval.tv_sec)
138 {
139 c->c2.timeval.tv_sec = (tv_sec_t)sec;
140 c->c2.timeval.tv_usec = 0;
141 }
142}
143
144void
146{
147 /* DCO context is not yet initialised or enabled */
148 if (!dco_enabled(&c->options))
149 {
150 return;
151 }
152
153 /* no active peer (p2p tls-server mode) */
154 if (c->c2.tls_multi->dco_peer_id == -1)
155 {
156 return;
157 }
158
159 if (!dco_update_keys(&c->c1.tuntap->dco, c->c2.tls_multi))
160 {
161 /* Something bad happened. Kill the connection to
162 * be able to recover. */
163 register_signal(c->sig, SIGUSR1, "dco update keys error");
164 }
165}
166
167/*
168 * In TLS mode, let TLS level respond to any control-channel
169 * packets which were received, or prepare any packets for
170 * transmission.
171 *
172 * tmp_int is purely an optimization that allows us to call
173 * tls_multi_process less frequently when there's not much
174 * traffic on the control-channel.
175 *
176 */
177static void
179{
180 interval_t wakeup = BIG_TIMEOUT;
181
182 if (interval_test(&c->c2.tmp_int))
183 {
184 const int tmp_status = tls_multi_process(
185 c->c2.tls_multi, &c->c2.to_link, &c->c2.to_link_addr, get_link_socket_info(c), &wakeup);
186
187 if (tmp_status == TLSMP_RECONNECT)
188 {
191 }
192
193 if (tmp_status == TLSMP_ACTIVE || tmp_status == TLSMP_RECONNECT)
194 {
195 update_time();
197 }
198 else if (tmp_status == TLSMP_KILL)
199 {
200 if (c->options.mode == MODE_SERVER)
201 {
203 }
204 else
205 {
206 register_signal(c->sig, SIGTERM, "auth-control-exit");
207 }
208 }
209 else if (tmp_status == TLSMP_RESTART)
210 {
211 /* The session cannot recover on its own. Kill the connection so
212 * that it is set up again from scratch */
213 register_signal(c->sig, SIGUSR1, "dco key state desync");
214 }
215
217 }
218
219 interval_schedule_wakeup(&c->c2.tmp_int, &wakeup);
220
221 /*
222 * Our current code has no good hooks in the TLS machinery to update
223 * DCO keys. So we check the key status after the whole TLS machinery
224 * has been completed and potentially update them
225 *
226 * We have a hidden state transition from secondary to primary key based
227 * on ks->auth_deferred_expire that DCO needs to check that the normal
228 * TLS state engine does not check. So we call the \c check_dco_key_status
229 * function even if tmp_status does not indicate that something has changed.
230 */
232
233 if (wakeup)
234 {
235 context_reschedule_sec(c, wakeup);
236 }
237}
238
239static void
241{
242 if (buf_string_match_head_str(buf, "AUTH_FAILED"))
243 {
244 receive_auth_failed(c, buf);
245 }
246 else if (buf_string_match_head_str(buf, "PUSH_"))
247 {
248 incoming_push_message(c, buf);
249 }
250 else if (buf_string_match_head_str(buf, "RESTART"))
251 {
252 server_pushed_signal(c, buf, true, 7);
253 }
254 else if (buf_string_match_head_str(buf, "HALT"))
255 {
256 server_pushed_signal(c, buf, false, 4);
257 }
258 else if (buf_string_match_head_str(buf, "INFO_PRE"))
259 {
260 server_pushed_info(buf, 8);
261 }
262 else if (buf_string_match_head_str(buf, "INFO"))
263 {
264 server_pushed_info(buf, 4);
265 }
266 else if (buf_string_match_head_str(buf, "CR_RESPONSE"))
267 {
268 receive_cr_response(c, buf);
269 }
270 else if (buf_string_match_head_str(buf, "AUTH_PENDING"))
271 {
272 receive_auth_pending(c, buf);
273 }
274 else if (buf_string_match_head_str(buf, "EXIT"))
275 {
277 }
278 else
279 {
280 msg(D_PUSH_ERRORS, "WARNING: Received unknown control message: %s", CBSTR(buf));
281 }
282}
283
284/*
285 * Handle incoming configuration
286 * messages on the control channel.
287 */
288static void
290{
291 int len = tls_test_payload_len(c->c2.tls_multi);
292 /* We should only be called with len >0 */
293 ASSERT(len > 0);
294
295 struct gc_arena gc = gc_new();
296 struct buffer buf = alloc_buf_gc(len, &gc);
297 if (tls_rec_payload(c->c2.tls_multi, &buf))
298 {
299 while (BLEN(&buf) > 1)
300 {
301 struct buffer cmdbuf = extract_command_buffer(&buf, &gc);
302
303 if (cmdbuf.len > 0)
304 {
306 }
307 }
308 }
309 else
310 {
311 msg(D_PUSH_ERRORS, "WARNING: Receive control message failed");
312 }
313
314 gc_free(&gc);
315}
316
317/*
318 * Periodically resend PUSH_REQUEST until PUSH message received
319 */
320static void
322{
324
325 /* if no response to first push_request, retry at PUSH_REQUEST_INTERVAL second intervals */
327}
328
329/*
330 * Things that need to happen immediately after connection initiation should go here.
331 *
332 * Options like --up-delay need to be triggered by this function which
333 * checks for connection establishment.
334 *
335 * Note: The process_incoming_push_reply currently assumes that this function
336 * only sets up the pull request timer when pull is enabled.
337 */
338static void
340{
342 {
343 /* if --pull was specified, send a push request to server */
344 if (c->c2.tls_multi && c->options.pull)
345 {
346#ifdef ENABLE_MANAGEMENT
347 if (management)
348 {
350 NULL);
351 }
352#endif
353 /* fire up push request right away (already 1s delayed) */
354 /* We might receive a AUTH_PENDING request before we armed this
355 * timer. In that case we don't change the value */
356 if (c->c2.push_request_timeout < now)
357 {
359 }
362 }
363 else
364 {
365 if (!do_up(c, false, 0))
366 {
367 register_signal(c->sig, SIGUSR1, "connection initialisation failed");
368 }
369 }
370
372 }
373}
374
375bool
377 msglvl_t msglevel)
378{
379 struct gc_arena gc = gc_new();
380 bool stat;
381
383 struct key_state *ks = &session->key[KS_PRIMARY];
384
385 /* buffered cleartext write onto TLS control channel */
386 stat = tls_send_payload(ks, (uint8_t *)str, strlen(str) + 1);
387
388 msg(msglevel, "SENT CONTROL [%s]: '%s' (status=%d)",
389 session->common_name ? session->common_name : "UNDEF", sanitize_control_message(str, &gc),
390 (int)stat);
391
392 gc_free(&gc);
393 return stat;
394}
395
396void
398{
400 context_immediate_reschedule(c); /* ZERO-TIMEOUT */
401}
402
403bool
404send_control_channel_string(struct context *c, const char *str, msglvl_t msglevel)
405{
406 if (c->c2.tls_multi)
407 {
409 bool ret = send_control_channel_string_dowork(session, str, msglevel);
411
412 return ret;
413 }
414 return true;
415}
416/*
417 * Add routes.
418 */
419
420static void
421check_add_routes_action(struct context *c, const bool errors)
422{
423 bool route_status = do_route(&c->options, c->c1.route_list, c->c1.route_ipv6_list, c->c1.tuntap,
424 c->plugins, c->c2.es, &c->net_ctx);
425
426 int flags = (errors ? ISC_ERRORS : 0);
427 flags |= (!route_status ? ISC_ROUTE_ERRORS : 0);
428
429 update_time();
432 initialization_sequence_completed(c, flags); /* client/p2p --route-delay was defined */
433}
434
435static void
437{
438 if (test_routes(c->c1.route_list, c->c1.tuntap))
439 {
440 check_add_routes_action(c, false);
441 }
443 {
445 }
446 else
447 {
448 msg(D_ROUTE, "Route: Waiting for TUN/TAP interface to come up...");
449 if (c->c1.tuntap)
450 {
451 if (!tun_standby(c->c1.tuntap))
452 {
453 register_signal(c->sig, SIGHUP, "ip-fail");
455#ifdef _WIN32
458#endif
459 }
460 }
461 update_time();
462 if (c->c2.route_wakeup.n != 1)
463 {
465 }
467 }
468}
469
470/*
471 * Should we exit due to inactivity timeout?
472 *
473 * In the non-dco case, the timeout is reset via register_activity()
474 * whenever there is sufficient activity on tun or link, so this function
475 * is only ever called to raise the TERM signal.
476 *
477 * With DCO, OpenVPN does not see incoming or outgoing data packets anymore
478 * and the logic needs to change - we permit the event to trigger and check
479 * kernel DCO counters here, returning and rearming the timer if there was
480 * sufficient traffic.
481 *
482 * NOTE: FreeBSD DCO does not supply "tun bytes" (= decrypted payload) today,
483 * so "dco bytes" (encrypted bytes, including keepalives) is used instead
484 */
485static void
487{
488 if (dco_enabled(&c->options) && dco_get_peer_stats(c, true) == 0)
489 {
490#ifdef TARGET_FREEBSD
491 int64_t tot_bytes = c->c2.dco_read_bytes + c->c2.dco_write_bytes;
492#else
493 int64_t tot_bytes = c->c2.tun_read_bytes + c->c2.tun_write_bytes;
494#endif
495 int64_t new_bytes = tot_bytes - c->c2.inactivity_bytes;
496
497 if (new_bytes > c->options.inactivity_minimum_bytes)
498 {
499 c->c2.inactivity_bytes = tot_bytes;
501 return;
502 }
503 }
504
505 msg(M_INFO, "Inactivity timeout (--inactive), exiting");
506 register_signal(c->sig, SIGTERM, "inactive");
507}
508
509int
511{
512 update_time();
513 int remaining = event_timeout_remaining(server_poll_timeout);
514 return max_int(0, remaining);
515}
516
517static void
519{
521 ASSERT(c->c2.tls_multi);
523 {
524 msg(M_INFO, "Server poll timeout, restarting");
525 register_signal(c->sig, SIGUSR1, "server_poll");
527 }
528}
529
530/*
531 * Schedule a SIGTERM signal c->options.scheduled_exit_interval seconds from now.
532 */
533bool
535{
536 const int n_seconds = c->options.scheduled_exit_interval;
537 /* don't reschedule if already scheduled. */
539 {
540 return false;
541 }
542
543 /* DCO iroutes must be removed now, because the delay introduced by this
544 * timer can create a race condition:
545 * the same client may reconnect before the old instance is purged, leading
546 * to DCO iroutes removal *after* reconnection, thus killing the routes
547 * for the new instance too.
548 *
549 * Standard/virtual iroutes (non-DCO case) are not affected because the
550 * last connecting client claiming the iroutes takes ownership. Therefore
551 * they are not removed during delayed cleanup.
552 */
553 if (c->did_dco_iroutes)
554 {
555 c->did_dco_iroutes = false;
557 }
558
560 update_time();
562 event_timeout_init(&c->c2.scheduled_exit, n_seconds, now);
564 msg(D_SCHED_EXIT, "Delayed exit in %d seconds", n_seconds);
565 return true;
566}
567
568/*
569 * Scheduled exit?
570 */
571static void
573{
574 register_signal(c->sig, c->c2.scheduled_exit_signal, "delayed-exit");
575}
576
577/*
578 * Should we write timer-triggered status file.
579 */
580static void
582{
583 if (c->c1.status_output)
584 {
586 }
587}
588
589#ifdef ENABLE_FRAGMENT
590/*
591 * Should we deliver a datagram fragment to remote?
592 * c is expected to be a single-link context (p2p or child)
593 */
594static void
596{
597 struct link_socket_info *lsi = get_link_socket_info(c);
598
599 /* OS MTU Hint? */
600 if (lsi->mtu_changed && lsi->lsa)
601 {
603 lsi->mtu_changed = false;
604 }
605
607 {
608 if (!c->c2.to_link.len)
609 {
610 /* encrypt a fragment for output to TCP/UDP port */
612 encrypt_sign(c, false);
613 }
614 }
615
617}
618#endif /* ifdef ENABLE_FRAGMENT */
619
620/*
621 * Buffer reallocation, for use with null encryption.
622 */
623static inline void
624buffer_turnover(const uint8_t *orig_buf, struct buffer *dest_stub, struct buffer *src_stub,
625 struct buffer *storage)
626{
627 if (orig_buf == src_stub->data && src_stub->data != storage->data)
628 {
629 buf_assign(storage, src_stub);
630 *dest_stub = *storage;
631 }
632 else
633 {
634 *dest_stub = *src_stub;
635 }
636}
637
638/*
639 * Compress, fragment, encrypt and HMAC-sign an outgoing packet.
640 * Input: c->c2.buf
641 * Output: c->c2.to_link
642 */
643void
644encrypt_sign(struct context *c, bool comp_frag)
645{
646 struct context_buffers *b = c->c2.buffers;
647 const uint8_t *orig_buf = c->c2.buf.data;
648 struct crypto_options *co = NULL;
649
650 if (dco_enabled(&c->options))
651 {
652 msg(M_WARN, "Attempting to send data packet while data channel offload is in use. "
653 "Dropping packet");
654 c->c2.buf.len = 0;
655 }
656
657 /*
658 * Drop non-TLS outgoing packet if client-connect script/plugin
659 * has not yet succeeded. In non-TLS tls_multi mode is not defined
660 * and we always pass packets.
661 */
663 {
664 c->c2.buf.len = 0;
665 }
666
667 if (comp_frag)
668 {
669#ifdef USE_COMP
670 /* Compress the packet. */
671 if (c->c2.comp_context)
672 {
673 (*c->c2.comp_context->alg.compress)(&c->c2.buf, b->compress_buf, c->c2.comp_context,
674 &c->c2.frame);
675 }
676#endif
677#ifdef ENABLE_FRAGMENT
678 if (c->c2.fragment)
679 {
681 }
682#endif
683 }
684
685 /* initialize work buffer with buf.headroom bytes of prepend capacity */
687
688 if (c->c2.tls_multi)
689 {
690 /* Get the key we will use to encrypt the packet. */
691 tls_pre_encrypt(c->c2.tls_multi, &c->c2.buf, &co);
692 /* If using P_DATA_V2, prepend the 1-byte opcode and 3-byte peer-id to the
693 * packet before openvpn_encrypt(), so we can authenticate the opcode too.
694 */
695 if (c->c2.buf.len > 0 && c->c2.tls_multi->use_peer_id)
696 {
698 }
699 }
700 else
701 {
702 co = &c->c2.crypto_options;
703 }
704
705 /* Encrypt and authenticate the packet */
706 openvpn_encrypt(&c->c2.buf, b->encrypt_buf, co);
707
708 /* Do packet administration */
709 if (c->c2.tls_multi)
710 {
711 if (c->c2.buf.len > 0 && !c->c2.tls_multi->use_peer_id)
712 {
714 }
716 }
717
718 /*
719 * Get the address we will be sending the packet to.
720 */
722
723 /* if null encryption, copy result to read_tun_buf */
724 buffer_turnover(orig_buf, &c->c2.to_link, &c->c2.buf, &b->read_tun_buf);
725}
726
727/*
728 * Should we exit due to session timeout?
729 */
730static void
732{
735 {
736 msg(M_INFO, "Session timeout, exiting");
737 register_signal(c->sig, SIGTERM, "session-timeout");
738 }
739}
740
741/*
742 * Coarse timers work to 1 second resolution.
743 */
744static void
746{
747 /* flush current packet-id to file once per 60
748 * seconds if --replay-persist was specified */
751 {
753 }
754
755 /* Should we write timer-triggered status file */
756 if (c->c1.status_output
758 {
760 }
761
762 /* process connection establishment items */
764 {
766 }
767
768 /* see if we should send a push_request (option --pull) */
770 {
772 }
773
774 /* process --route options */
776 {
778 }
779
780 /* check if we want to refresh the auth-token */
782 {
784 }
785
786 /* possibly exit due to --inactive */
789 {
791 }
792
793 if (c->sig->signal_received)
794 {
795 return;
796 }
797
798 /* kill session if time is over */
800 if (c->sig->signal_received)
801 {
802 return;
803 }
804
805 /* restart if ping not received */
807 if (c->sig->signal_received)
808 {
809 return;
810 }
811
812 if (c->c2.tls_multi)
813 {
816 {
818 }
819 if (c->sig->signal_received)
820 {
821 return;
822 }
824 {
826 }
827 if (c->sig->signal_received)
828 {
829 return;
830 }
831 }
832
833 /* Should we send an OCC_REQUEST message? */
835
836 /* Should we send an MTU load test? */
838
839 /* Should we send an OCC_EXIT message to remote? */
841 {
843 }
844
845 /* Should we ping the remote? */
847
848#ifdef ENABLE_MANAGEMENT
849 if (management)
850 {
852 }
853#endif /* ENABLE_MANAGEMENT */
854}
855
856static void
858{
859 if (now < c->c2.coarse_timer_wakeup)
860 {
862 return;
863 }
864
865 const struct timeval save = c->c2.timeval;
866 c->c2.timeval.tv_sec = BIG_TIMEOUT;
867 c->c2.timeval.tv_usec = 0;
869 c->c2.coarse_timer_wakeup = now + c->c2.timeval.tv_sec;
870
871 dmsg(D_INTERVAL, "TIMER: coarse timer wakeup %" PRIi64 " seconds",
872 (int64_t)c->c2.timeval.tv_sec);
873
874 /* Is the coarse timeout NOT the earliest one? */
875 if (c->c2.timeval.tv_sec > save.tv_sec)
876 {
877 c->c2.timeval = save;
878 }
879}
880
881static void
883{
884 const int update_interval = 10; /* seconds */
885 c->c2.update_timeout_random_component = now + update_interval;
886 c->c2.timeout_random_component.tv_usec = (time_t)get_random() & 0x0003FFFF;
887 c->c2.timeout_random_component.tv_sec = 0;
888
889 dmsg(D_INTERVAL, "RANDOM USEC=%ld", (long)c->c2.timeout_random_component.tv_usec);
890}
891
892static inline void
894{
896 {
898 }
899 if (c->c2.timeval.tv_sec >= 1)
900 {
902 }
903}
904
905/*
906 * Handle addition and removal of the 10-byte Socks5 header
907 * in UDP packets.
908 */
909
910static inline void
912{
913 if (sock->socks_proxy && sock->info.proto == PROTO_UDP)
914 {
916 }
917}
918
919static inline void
921 struct link_socket_actual **to_addr, int *size_delta)
922{
923 if (sock->socks_proxy && sock->info.proto == PROTO_UDP)
924 {
925 *size_delta += socks_process_outgoing_udp(&c->c2.to_link, c->c2.to_link_addr);
926 *to_addr = &sock->socks_relay;
927 }
928}
929
930/* undo effect of socks_preprocess_outgoing_link */
931static inline void
932link_socket_write_post_size_adjust(int *size, int size_delta, struct buffer *buf)
933{
934 if (size_delta > 0 && *size > size_delta)
935 {
936 *size -= size_delta;
937 if (!buf_advance(buf, size_delta))
938 {
939 *size = 0;
940 }
941 }
942}
943
944/*
945 * Output: c->c2.buf
946 */
947
948void
949read_incoming_link(struct context *c, struct link_socket *sock)
950{
951 /*
952 * Set up for recvfrom call to read datagram
953 * sent to our TCP/UDP port.
954 */
955 /*ASSERT (!c->c2.to_tun.len);*/
956
957 c->c2.buf = c->c2.buffers->read_link_buf;
959
960 ssize_t status = link_socket_read(sock, &c->c2.buf, &c->c2.from);
961
963 {
964#if PORT_SHARE
965 if (port_share && socket_foreign_protocol_detected(sock))
966 {
967 const struct buffer *fbuf = socket_foreign_protocol_head(sock);
968 const int sd = socket_foreign_protocol_sd(sock);
969 port_share_redirect(port_share, fbuf, sd);
970 register_signal(c->sig, SIGTERM, "port-share-redirect");
971 }
972 else
973#endif
974 {
975 /* received a disconnect from a connection-oriented protocol */
977 {
979 "Connection reset during exit notification period, ignoring [%zd]", status);
981 }
982 else
983 {
985 "connection-reset"); /* SOFT-SIGUSR1 -- TCP connection reset */
986 msg(D_STREAM_ERRORS, "Connection reset, restarting [%zd]", status);
987 }
988 }
989 return;
990 }
991
992 /* check_status() call below resets last-error code */
993 bool dco_win_timeout = tuntap_is_dco_win_timeout(c->c1.tuntap, status);
994
995 /* check recvfrom status */
996 check_status(status, "read", sock, NULL);
997
998 if (dco_win_timeout)
999 {
1001 }
1002
1003 /* Remove socks header if applicable */
1005}
1006
1007bool
1008process_incoming_link_part1(struct context *c, struct link_socket_info *lsi, bool floated)
1009{
1010 struct gc_arena gc = gc_new();
1011 bool decrypt_status = false;
1012
1013 if (c->c2.buf.len > 0)
1014 {
1015 c->c2.link_read_bytes += c->c2.buf.len;
1017 c->c2.original_recv_size = c->c2.buf.len;
1018 }
1019 else
1020 {
1021 c->c2.original_recv_size = 0;
1022 }
1023
1024#ifdef ENABLE_DEBUG
1025 /* take action to corrupt packet if we are in gremlin test mode */
1026 if (c->options.gremlin)
1027 {
1028 if (!ask_gremlin(c->options.gremlin))
1029 {
1030 c->c2.buf.len = 0;
1031 }
1032 corrupt_gremlin(&c->c2.buf, c->options.gremlin);
1033 }
1034#endif
1035
1036 /* log incoming packet */
1037#ifdef LOG_RW
1038 if (c->c2.log_rw && c->c2.buf.len > 0)
1039 {
1040 fprintf(stderr, "R");
1041 }
1042#endif
1043 msg(D_LINK_RW, "%s READ [%d] from %s: %s", proto2ascii(lsi->proto, lsi->af, true),
1044 BLEN(&c->c2.buf), print_link_socket_actual(&c->c2.from, &gc), PROTO_DUMP(&c->c2.buf, &gc));
1045
1046 /*
1047 * Good, non-zero length packet received.
1048 * Commence multi-stage processing of packet,
1049 * such as authenticate, decrypt, decompress.
1050 * If any stage fails, it sets buf.len to 0,
1051 * telling downstream stages to ignore the packet.
1052 */
1053 if (c->c2.buf.len > 0)
1054 {
1055 struct crypto_options *co = NULL;
1056 const uint8_t *ad_start = NULL;
1057 if (!link_socket_verify_incoming_addr(&c->c2.buf, lsi, &c->c2.from))
1058 {
1060 }
1061
1062 if (c->c2.tls_multi)
1063 {
1064 uint8_t opcode = *BPTR(&c->c2.buf) >> P_OPCODE_SHIFT;
1065
1066 /*
1067 * If DCO is enabled, the kernel drivers require that the
1068 * other end only sends P_DATA_V2 packets. V1 are unknown
1069 * to kernel and passed to userland, but we cannot handle them
1070 * either because crypto context is missing - so drop the packet.
1071 *
1072 * This can only happen with particular old (2.4.0-2.4.4) servers.
1073 */
1074 if ((opcode == P_DATA_V1) && dco_enabled(&c->options))
1075 {
1076 msg(D_LINK_ERRORS, "Data Channel Offload doesn't support DATA_V1 packets. "
1077 "Upgrade your server to 2.4.5 or newer.");
1078 c->c2.buf.len = 0;
1079 }
1080
1081 /*
1082 * If tls_pre_decrypt returns true, it means the incoming
1083 * packet was a good TLS control channel packet. If so, TLS code
1084 * will deal with the packet and set buf.len to 0 so downstream
1085 * stages ignore it.
1086 *
1087 * If the packet is a data channel packet, tls_pre_decrypt
1088 * will load crypto_options with the correct encryption key
1089 * and return false.
1090 */
1091 if (tls_pre_decrypt(c->c2.tls_multi, &c->c2.from, &c->c2.buf, &co, floated, &ad_start))
1092 {
1094
1095 /* reset packet received timer if TLS packet */
1097 {
1099 }
1100 }
1101 }
1102 else
1103 {
1104 co = &c->c2.crypto_options;
1105 }
1106
1107 /*
1108 * Drop non-TLS packet if client-connect script/plugin and cipher selection
1109 * has not yet succeeded. In non-TLS mode tls_multi is not defined
1110 * and we always pass packets.
1111 */
1113 {
1114 c->c2.buf.len = 0;
1115 }
1116
1117 /* authenticate and decrypt the incoming packet */
1118 decrypt_status =
1119 openvpn_decrypt(&c->c2.buf, c->c2.buffers->decrypt_buf, co, &c->c2.frame, ad_start);
1120
1121 if (!decrypt_status
1122 /* on the instance context we have only one socket, so just check the first one */
1124 {
1125 /* decryption errors are fatal in TCP mode */
1127 "decryption-error"); /* SOFT-SIGUSR1 -- decryption error in TCP mode */
1128 msg(D_STREAM_ERRORS, "Fatal decryption error (process_incoming_link), restarting");
1129 }
1130 }
1131 else
1132 {
1133 buf_reset(&c->c2.to_tun);
1134 }
1135 gc_free(&gc);
1136
1137 return decrypt_status;
1138}
1139
1140void
1142 const uint8_t *orig_buf)
1143{
1144 if (c->c2.buf.len > 0)
1145 {
1146#ifdef ENABLE_FRAGMENT
1147 if (c->c2.fragment)
1148 {
1150 }
1151#endif
1152
1153#ifdef USE_COMP
1154 /* decompress the incoming packet */
1155 if (c->c2.comp_context)
1156 {
1157 (*c->c2.comp_context->alg.decompress)(&c->c2.buf, c->c2.buffers->decompress_buf,
1158 c->c2.comp_context, &c->c2.frame);
1159 }
1160#endif
1161
1162#ifdef PACKET_TRUNCATION_CHECK
1163 /* if (c->c2.buf.len > 1) --c->c2.buf.len; */
1164 ipv4_packet_size_verify(BPTR(&c->c2.buf), BLEN(&c->c2.buf), TUNNEL_TYPE(c->c1.tuntap),
1165 "POST_DECRYPT", &c->c2.n_trunc_post_decrypt);
1166#endif
1167
1168 /*
1169 * Set our "official" outgoing address, since
1170 * if buf.len is non-zero, we know the packet
1171 * authenticated. In TLS mode we do nothing
1172 * because TLS mode takes care of source address
1173 * authentication.
1174 *
1175 * Also, update the persisted version of our packet-id.
1176 */
1177 if (!TLS_MODE(c) && c->c2.buf.len > 0)
1178 {
1179 link_socket_set_outgoing_addr(lsi, &c->c2.from, NULL, c->c2.es);
1180 }
1181
1182 /* reset packet received timer */
1183 if (c->options.ping_rec_timeout && c->c2.buf.len > 0)
1184 {
1186 }
1187
1188 /* increment authenticated receive byte count */
1189 if (c->c2.buf.len > 0)
1190 {
1191 c->c2.link_read_bytes_auth += c->c2.buf.len;
1194 }
1195
1196 /* Did we just receive an openvpn ping packet? */
1197 if (is_ping_msg(&c->c2.buf))
1198 {
1199 dmsg(D_PING, "RECEIVED PING PACKET");
1200 c->c2.buf.len = 0; /* drop packet */
1201 }
1202
1203 /* Did we just receive an OCC packet? */
1204 if (is_occ_msg(&c->c2.buf))
1205 {
1207 }
1208
1209 buffer_turnover(orig_buf, &c->c2.to_tun, &c->c2.buf, &c->c2.buffers->read_link_buf);
1210
1211 /* to_tun defined + unopened tuntap can cause deadlock */
1212 if (!tuntap_defined(c->c1.tuntap))
1213 {
1214 c->c2.to_tun.len = 0;
1215 }
1216 }
1217 else
1218 {
1219 buf_reset(&c->c2.to_tun);
1220 }
1221}
1222
1223static void
1225{
1226 struct link_socket_info *lsi = &sock->info;
1227 const uint8_t *orig_buf = c->c2.buf.data;
1228
1229 process_incoming_link_part1(c, lsi, false);
1230 process_incoming_link_part2(c, lsi, orig_buf);
1231}
1232
1233void
1234extract_dco_float_peer_addr(const sa_family_t socket_family, struct openvpn_sockaddr *out_osaddr,
1235 const struct sockaddr *float_sa)
1236{
1237 if (float_sa->sa_family == AF_INET)
1238 {
1239 const struct sockaddr_in *float4 = (struct sockaddr_in *)float_sa;
1240 /* DCO treats IPv4-mapped IPv6 addresses as pure IPv4. However, on a
1241 * dual-stack socket, we need to preserve the mapping otherwise openvpn
1242 * will not be able to find the peer by its transport address.
1243 */
1244 if (socket_family == AF_INET6)
1245 {
1246 out_osaddr->addr.in6.sin6_family = AF_INET6;
1247 out_osaddr->addr.in6.sin6_port = float4->sin_port;
1248
1249 memset(&out_osaddr->addr.in6.sin6_addr.s6_addr, 0, 10);
1250 out_osaddr->addr.in6.sin6_addr.s6_addr[10] = 0xff;
1251 out_osaddr->addr.in6.sin6_addr.s6_addr[11] = 0xff;
1252 memcpy(&out_osaddr->addr.in6.sin6_addr.s6_addr[12], &float4->sin_addr.s_addr,
1253 sizeof(in_addr_t));
1254 }
1255 else
1256 {
1257 memcpy(&out_osaddr->addr.in4, float4, sizeof(struct sockaddr_in));
1258 }
1259 }
1260 else
1261 {
1262 const struct sockaddr_in6 *float6 = (struct sockaddr_in6 *)float_sa;
1263 memcpy(&out_osaddr->addr.in6, float6, sizeof(struct sockaddr_in6));
1264 }
1265}
1266
1267void
1269{
1270#if defined(ENABLE_DCO) && (defined(TARGET_LINUX) || defined(TARGET_FREEBSD))
1271 struct context *c = dco->c;
1272
1273 /* FreeBSD currently sends us removal notifcation with the old peer-id in
1274 * p2p mode with the ping timeout reason, so ignore that one to not shoot
1275 * ourselves in the foot and removing the just established session */
1276 if (dco->dco_message_peer_id != c->c2.tls_multi->dco_peer_id)
1277 {
1279 "%s: received message for mismatching peer-id %d, "
1280 "expected %d",
1281 __func__, dco->dco_message_peer_id, c->c2.tls_multi->dco_peer_id);
1282 return;
1283 }
1284
1285 switch (dco->dco_message_type)
1286 {
1287 case OVPN_CMD_DEL_PEER:
1288 /* peer is gone, unset ID to prevent more kernel calls */
1289 c->c2.tls_multi->dco_peer_id = -1;
1290 if (dco->dco_del_peer_reason == OVPN_DEL_PEER_REASON_EXPIRED)
1291 {
1293 "%s: received peer expired notification of for peer-id "
1294 "%d",
1295 __func__, dco->dco_message_peer_id);
1297 return;
1298 }
1299 break;
1300
1301 case OVPN_CMD_SWAP_KEYS:
1302 msg(D_DCO_DEBUG, "%s: received key rotation notification for peer-id %d", __func__,
1303 dco->dco_message_peer_id);
1305 break;
1306
1307 default:
1308 msg(D_DCO_DEBUG, "%s: received message of type %d - ignoring", __func__,
1309 dco->dco_message_type);
1310 return;
1311 }
1312
1313#endif /* if defined(ENABLE_DCO) && (defined(TARGET_LINUX) || defined(TARGET_FREEBSD)) */
1314}
1315
1316/*
1317 * Output: c->c2.buf
1318 */
1319
1320void
1322{
1323 /*
1324 * Setup for read() call on TUN/TAP device.
1325 */
1326 /*ASSERT (!c->c2.to_link.len);*/
1327
1328 c->c2.buf = c->c2.buffers->read_tun_buf;
1329
1330#ifdef _WIN32
1331 /* we cannot end up here when using dco */
1332 ASSERT(!dco_enabled(&c->options));
1333
1334 sockethandle_t sh = { .is_handle = true, .h = c->c1.tuntap->hand, .prepend_sa = false };
1335 sockethandle_finalize(sh, &c->c1.tuntap->reads, &c->c2.buf, NULL);
1336#else /* ifdef _WIN32 */
1340 {
1341 c->c2.buf.len =
1343 }
1344 else
1345 {
1346 c->c2.buf.len = (int)read_tun(c->c1.tuntap, BPTR(&c->c2.buf), c->c2.frame.buf.payload_size);
1347 }
1348#endif /* ifdef _WIN32 */
1349
1350#ifdef PACKET_TRUNCATION_CHECK
1351 ipv4_packet_size_verify(BPTR(&c->c2.buf), BLEN(&c->c2.buf), TUNNEL_TYPE(c->c1.tuntap),
1352 "READ_TUN", &c->c2.n_trunc_tun_read);
1353#endif
1354
1355 /* Was TUN/TAP interface stopped? */
1356 if (tuntap_stop(c->c2.buf.len))
1357 {
1358 register_signal(c->sig, SIGTERM, "tun-stop");
1359 msg(M_INFO, "TUN/TAP interface has been stopped, exiting");
1360 return;
1361 }
1362
1363 /* Was TUN/TAP I/O operation aborted? */
1364 if (tuntap_abort(c->c2.buf.len))
1365 {
1366 register_signal(c->sig, SIGHUP, "tun-abort");
1368 msg(M_INFO, "TUN/TAP I/O operation aborted, restarting");
1369 return;
1370 }
1371
1372 /* Check the status return from read() */
1373 check_status(c->c2.buf.len, "read from TUN/TAP", NULL, c->c1.tuntap);
1374}
1375
1384static void
1386{
1387 if (c->c2.to_link_addr == NULL) /* no remote addr known */
1388 {
1389 return;
1390 }
1391
1392 const struct openvpn_sockaddr *link_addr = &c->c2.to_link_addr->dest;
1393 const struct link_socket_info *lsi = get_link_socket_info(c);
1394
1395 int ip_hdr_offset = 0;
1396 int tun_ip_ver = get_tun_ip_ver(TUNNEL_TYPE(c->c1.tuntap), buf, &ip_hdr_offset);
1397
1398 if (tun_ip_ver == 4)
1399 {
1400 /* Ensure we can safely read the IPv4 header */
1401 const int min_ip_header = ip_hdr_offset + sizeof(struct openvpn_iphdr);
1402 if (BLEN(buf) < min_ip_header)
1403 {
1404 return;
1405 }
1406
1407 struct openvpn_iphdr *pip = (struct openvpn_iphdr *)(BPTR(buf) + ip_hdr_offset);
1408 const int ip_hlen = OPENVPN_IPH_GET_LEN(pip->version_len);
1409 /* Reject malformed or truncated headers */
1410 if (ip_hlen < (int)sizeof(struct openvpn_iphdr)
1411 || BLENZ(buf) < ip_hdr_offset + ip_hlen + sizeof(uint16_t) * 2)
1412 {
1413 return;
1414 }
1415
1416 /* skip ipv4 packets for ipv6 tun */
1417 if (link_addr->addr.sa.sa_family != AF_INET)
1418 {
1419 return;
1420 }
1421
1422 /* skip if tun protocol doesn't match link protocol */
1423 if ((lsi->proto == PROTO_TCP && pip->protocol != OPENVPN_IPPROTO_TCP)
1424 || (lsi->proto == PROTO_UDP && pip->protocol != OPENVPN_IPPROTO_UDP))
1425 {
1426 return;
1427 }
1428
1429 /* drop packets with same dest addr and port as remote */
1430 const uint8_t *l4_hdr = (uint8_t *)pip + ip_hlen;
1431
1432 uint16_t link_port = ntohs(link_addr->addr.in4.sin_port);
1433
1434 /* TCP and UDP ports are at the same place in the header, and other protocols
1435 * can not happen here due to the lsi->proto check above */
1436 uint16_t src_port = ntohs(*(uint16_t *)l4_hdr);
1437 uint16_t dst_port = ntohs(*(uint16_t *)(l4_hdr + sizeof(uint16_t)));
1438 if ((memcmp(&link_addr->addr.in4.sin_addr.s_addr, &pip->daddr, sizeof(pip->daddr)) == 0) && (link_port == dst_port))
1439 {
1440 buf->len = 0;
1441
1442 struct gc_arena gc = gc_new();
1443 msg(D_LOW, "Recursive routing detected, packet dropped %s:%" PRIu16 " -> %s",
1445 src_port,
1447 gc_free(&gc);
1448 }
1449 }
1450 else if (tun_ip_ver == 6)
1451 {
1452 /* make sure we got whole IPv6 header and TCP/UDP src/dst ports */
1453 const int min_ipv6 = ip_hdr_offset + sizeof(struct openvpn_ipv6hdr) + sizeof(uint16_t) * 2;
1454 if (BLEN(buf) < min_ipv6)
1455 {
1456 return;
1457 }
1458
1459 /* skip ipv6 packets for ipv4 tun */
1460 if (link_addr->addr.sa.sa_family != AF_INET6)
1461 {
1462 return;
1463 }
1464
1465 struct openvpn_ipv6hdr *pip6 = (struct openvpn_ipv6hdr *)(BPTR(buf) + ip_hdr_offset);
1466
1467 /* skip if tun protocol doesn't match link protocol */
1468 if ((lsi->proto == PROTO_TCP && pip6->nexthdr != OPENVPN_IPPROTO_TCP)
1469 || (lsi->proto == PROTO_UDP && pip6->nexthdr != OPENVPN_IPPROTO_UDP))
1470 {
1471 return;
1472 }
1473
1474 uint16_t link_port = ntohs(link_addr->addr.in6.sin6_port);
1475
1476 /* drop packets with same dest addr and port as remote */
1477 const uint8_t *l4_hdr = (uint8_t *)pip6 + sizeof(struct openvpn_ipv6hdr);
1478 uint16_t src_port = ntohs(*(uint16_t *)l4_hdr);
1479 uint16_t dst_port = ntohs(*(uint16_t *)(l4_hdr + sizeof(uint16_t)));
1480 if ((OPENVPN_IN6_ARE_ADDR_EQUAL(&link_addr->addr.in6.sin6_addr, &pip6->daddr)) && (link_port == dst_port))
1481 {
1482 buf->len = 0;
1483
1484 struct gc_arena gc = gc_new();
1485 msg(D_LOW, "Recursive routing detected, packet dropped %s:%" PRIu16 " -> %s",
1486 print_in6_addr(pip6->saddr, IA_NET_ORDER, &gc),
1487 src_port,
1489 gc_free(&gc);
1490 }
1491 }
1492}
1493
1494/*
1495 * Input: c->c2.buf
1496 * Output: c->c2.to_link
1497 */
1498
1499void
1500process_incoming_tun(struct context *c, struct link_socket *out_sock)
1501{
1502 if (c->c2.buf.len > 0)
1503 {
1504 c->c2.tun_read_bytes += c->c2.buf.len;
1505 }
1506
1507#ifdef LOG_RW
1508 if (c->c2.log_rw && c->c2.buf.len > 0)
1509 {
1510 fprintf(stderr, "r");
1511 }
1512#endif
1513
1514 /* Show packet content */
1515 dmsg(D_TUN_RW, "TUN READ [%d]", BLEN(&c->c2.buf));
1516
1517 if (c->c2.buf.len > 0)
1518 {
1520 {
1522 }
1523 /*
1524 * The --passtos and --mssfix options require
1525 * us to examine the IP header (IPv4 or IPv6).
1526 */
1527 unsigned int flags =
1529 process_ip_header(c, flags, &c->c2.buf, out_sock);
1530
1531#ifdef PACKET_TRUNCATION_CHECK
1532 /* if (c->c2.buf.len > 1) --c->c2.buf.len; */
1533 ipv4_packet_size_verify(BPTR(&c->c2.buf), BLEN(&c->c2.buf), TUNNEL_TYPE(c->c1.tuntap),
1534 "PRE_ENCRYPT", &c->c2.n_trunc_pre_encrypt);
1535#endif
1536 }
1537 if (c->c2.buf.len > 0)
1538 {
1539 encrypt_sign(c, true);
1540 }
1541 else
1542 {
1543 buf_reset(&c->c2.to_link);
1544 }
1545}
1546
1557void
1558ipv6_send_icmp_unreachable(struct context *c, struct buffer *buf, bool client)
1559{
1560#define MAX_ICMPV6LEN 1280
1561 struct openvpn_icmp6hdr icmp6out;
1562 CLEAR(icmp6out);
1563
1564 /*
1565 * Get a buffer to the ip packet, is_ipv6 automatically forwards
1566 * the buffer to the ip packet
1567 */
1568 struct buffer inputipbuf = *buf;
1569
1570 is_ipv6(TUNNEL_TYPE(c->c1.tuntap), &inputipbuf);
1571
1572 if (BLEN(&inputipbuf) < (int)sizeof(struct openvpn_ipv6hdr))
1573 {
1574 return;
1575 }
1576
1577 const struct openvpn_ipv6hdr *pip6 = (struct openvpn_ipv6hdr *)BPTR(&inputipbuf);
1578
1579 /* Copy version, traffic class, flow label from input packet */
1580 struct openvpn_ipv6hdr pip6out = *pip6;
1581
1582 pip6out.version_prio = pip6->version_prio;
1583 pip6out.daddr = pip6->saddr;
1584
1585 /*
1586 * Use the IPv6 remote address if we have one, otherwise use a fake one
1587 * using the remote address is preferred since it makes debugging and
1588 * understanding where the ICMPv6 error originates easier
1589 */
1591 {
1592 inet_pton(AF_INET6, c->options.ifconfig_ipv6_remote, &pip6out.saddr);
1593 }
1594 else
1595 {
1596 inet_pton(AF_INET6, "fe80::7", &pip6out.saddr);
1597 }
1598
1600
1601 /*
1602 * The ICMPv6 unreachable code worked best in my (arne) tests with Windows,
1603 * Linux and Android. Windows did not like the administratively prohibited
1604 * return code (no fast fail)
1605 */
1608
1609 const int icmpheader_len = sizeof(struct openvpn_ipv6hdr) + sizeof(struct openvpn_icmp6hdr);
1610 int totalheader_len = icmpheader_len;
1611
1612 if (TUNNEL_TYPE(c->c1.tuntap) == DEV_TYPE_TAP)
1613 {
1614 totalheader_len += sizeof(struct openvpn_ethhdr);
1615 }
1616
1617 /*
1618 * Calculate size for payload, defined in the standard that the resulting
1619 * frame should be <= 1280 and have as much as possible of the original
1620 * packet
1621 */
1622 int max_payload_size = min_int(MAX_ICMPV6LEN, c->c2.frame.tun_mtu - icmpheader_len);
1623 /* Ensure that minimum payload size is at least 64 bytes as extra safety layer */
1624 max_payload_size = max_int(max_payload_size, 64);
1625 const int payload_len = min_int(max_payload_size, BLEN(&inputipbuf));
1626 const uint16_t icmp_len = (uint16_t)(sizeof(struct openvpn_icmp6hdr) + payload_len);
1627
1628 pip6out.payload_len = htons(icmp_len);
1629
1630 /* Construct the packet as outgoing packet back to the client */
1631 struct buffer *outbuf;
1632 if (client)
1633 {
1634 c->c2.to_tun = c->c2.buffers->aux_buf;
1635 outbuf = &(c->c2.to_tun);
1636 }
1637 else
1638 {
1639 c->c2.to_link = c->c2.buffers->aux_buf;
1640 outbuf = &(c->c2.to_link);
1641 }
1642 ASSERT(buf_init(outbuf, totalheader_len));
1643
1644 /* Fill the end of the buffer with original packet */
1645 ASSERT(buf_safe(outbuf, payload_len));
1646 ASSERT(buf_copy_n(outbuf, &inputipbuf, payload_len));
1647
1648 /* ICMP Header, copy into buffer to allow checksum calculation */
1649 ASSERT(buf_write_prepend(outbuf, &icmp6out, sizeof(struct openvpn_icmp6hdr)));
1650
1651 /* Calculate checksum over the packet and write to header */
1652
1653 uint16_t new_csum =
1654 ip_checksum(AF_INET6, BPTR(outbuf), BLEN(outbuf), (const uint8_t *)&pip6out.saddr,
1655 (uint8_t *)&pip6out.daddr, OPENVPN_IPPROTO_ICMPV6);
1656 ((struct openvpn_icmp6hdr *)BPTR(outbuf))->icmp6_cksum = htons(new_csum);
1657
1658
1659 /* IPv6 Header */
1660 ASSERT(buf_write_prepend(outbuf, &pip6out, sizeof(struct openvpn_ipv6hdr)));
1661
1662 /*
1663 * Tap mode, we also need to create an Ethernet header.
1664 */
1665 if (TUNNEL_TYPE(c->c1.tuntap) == DEV_TYPE_TAP)
1666 {
1667 if (BLEN(buf) < (int)sizeof(struct openvpn_ethhdr))
1668 {
1669 return;
1670 }
1671
1672 const struct openvpn_ethhdr *orig_ethhdr = (const struct openvpn_ethhdr *)CBPTR(buf);
1673
1674 /* Copy frametype and reverse source/destination for the response */
1675 struct openvpn_ethhdr ethhdr;
1676 memcpy(ethhdr.source, orig_ethhdr->dest, OPENVPN_ETH_ALEN);
1677 memcpy(ethhdr.dest, orig_ethhdr->source, OPENVPN_ETH_ALEN);
1678 ethhdr.proto = htons(OPENVPN_ETH_P_IPV6);
1679 ASSERT(buf_write_prepend(outbuf, &ethhdr, sizeof(struct openvpn_ethhdr)));
1680 }
1681#undef MAX_ICMPV6LEN
1682}
1683
1684void
1685process_ip_header(struct context *c, unsigned int flags, struct buffer *buf,
1686 struct link_socket *sock)
1687{
1688 if (!c->options.ce.mssfix)
1689 {
1690 flags &= ~PIP_MSSFIX;
1691 }
1692#if PASSTOS_CAPABILITY
1693 if (!c->options.passtos)
1694 {
1695 flags &= ~PIPV4_PASSTOS;
1696 }
1697#endif
1698 if (!c->options.client_nat)
1699 {
1700 flags &= ~PIPV4_CLIENT_NAT;
1701 }
1703 {
1705 }
1706 if (!c->options.block_ipv6)
1707 {
1709 }
1710
1711 if (buf->len > 0)
1712 {
1713 struct buffer ipbuf = *buf;
1714 if (is_ipv4(TUNNEL_TYPE(c->c1.tuntap), &ipbuf))
1715 {
1716#if PASSTOS_CAPABILITY
1717 /* extract TOS from IP header */
1718 if (flags & PIPV4_PASSTOS)
1719 {
1720 link_socket_extract_tos(sock, &ipbuf);
1721 }
1722#endif
1723
1724 /* possibly alter the TCP MSS */
1725 if (flags & PIP_MSSFIX)
1726 {
1727 mss_fixup_ipv4(&ipbuf, c->c2.frame.mss_fix);
1728 }
1729
1730 /* possibly do NAT on packet */
1731 if ((flags & PIPV4_CLIENT_NAT) && c->options.client_nat)
1732 {
1733 const int direction = (flags & PIP_OUTGOING) ? CN_INCOMING : CN_OUTGOING;
1734 client_nat_transform(c->options.client_nat, &ipbuf, direction);
1735 }
1736 /* possibly extract a DHCP router message */
1737 if (flags & PIPV4_EXTRACT_DHCP_ROUTER)
1738 {
1739 const in_addr_t dhcp_router = dhcp_extract_router_msg(&ipbuf);
1740 if (dhcp_router)
1741 {
1742 route_list_add_vpn_gateway(c->c1.route_list, c->c2.es, dhcp_router);
1743 }
1744 }
1745 }
1746 else if (is_ipv6(TUNNEL_TYPE(c->c1.tuntap), &ipbuf))
1747 {
1748 /* possibly alter the TCP MSS */
1749 if (flags & PIP_MSSFIX)
1750 {
1751 mss_fixup_ipv6(&ipbuf, c->c2.frame.mss_fix);
1752 }
1753 if (!(flags & PIP_OUTGOING)
1755 {
1757 /* Drop the IPv6 packet */
1758 buf->len = 0;
1759 }
1760 }
1761 }
1762}
1763
1764/*
1765 * Input: c->c2.to_link
1766 */
1767
1768void
1770{
1771 struct gc_arena gc = gc_new();
1772
1773 if (c->c2.to_link.len > 0 && c->c2.to_link.len <= c->c2.frame.buf.payload_size)
1774 {
1775 /*
1776 * Setup for call to send/sendto which will send
1777 * packet to remote over the TCP/UDP port.
1778 */
1779 int size = 0;
1781
1782#ifdef ENABLE_DEBUG
1783 /* In gremlin-test mode, we may choose to drop this packet */
1784 if (!c->options.gremlin || ask_gremlin(c->options.gremlin))
1785#endif
1786 {
1787 /*
1788 * Let the traffic shaper know how many bytes
1789 * we wrote.
1790 */
1791 if (c->options.shaper)
1792 {
1793 int overhead =
1794 datagram_overhead(c->c2.to_link_addr->dest.addr.sa.sa_family, sock->info.proto);
1795 shaper_wrote_bytes(&c->c2.shaper, BLEN(&c->c2.to_link) + overhead);
1796 }
1797
1798 /*
1799 * Let the pinger know that we sent a packet.
1800 */
1802 {
1804 }
1805
1806#if PASSTOS_CAPABILITY
1807 /* Set TOS */
1808 link_socket_set_tos(sock);
1809#endif
1810
1811 /* Log packet send */
1812#ifdef LOG_RW
1813 if (c->c2.log_rw)
1814 {
1815 fprintf(stderr, "W");
1816 }
1817#endif
1818 msg(D_LINK_RW, "%s WRITE [%d] to %s: %s",
1819 proto2ascii(sock->info.proto, sock->info.af, true), BLEN(&c->c2.to_link),
1821
1822 /* Packet send complexified by possible Socks5 usage */
1823 {
1824 struct link_socket_actual *to_addr = c->c2.to_link_addr;
1825 int size_delta = 0;
1826
1827 /* If Socks5 over UDP, prepend header */
1828 socks_preprocess_outgoing_link(c, sock, &to_addr, &size_delta);
1829
1830 /* Send packet */
1831 size = (int)link_socket_write(sock, &c->c2.to_link, to_addr);
1832
1833 /* Undo effect of prepend */
1834 link_socket_write_post_size_adjust(&size, size_delta, &c->c2.to_link);
1835 }
1836
1837 if (size > 0)
1838 {
1840 c->c2.link_write_bytes += size;
1842 }
1843 }
1844
1845 /* Check return status */
1846 int error_code = openvpn_errno();
1847 check_status(size, "write", sock, NULL);
1848
1849 if (size > 0)
1850 {
1851 /* Did we write a different size packet than we intended? */
1852 if (size != BLEN(&c->c2.to_link))
1853 {
1855 "TCP/UDP packet was truncated/expanded on write to %s (tried=%d,actual=%d)",
1857 }
1858 }
1859
1860 /* if not a ping/control message, indicate activity regarding --inactive parameter */
1861 if (c->c2.buf.len > 0)
1862 {
1863 register_activity(c, size);
1864 }
1865
1866 /* for unreachable network and "connecting" state switch to the next host */
1867
1868 bool unreachable = error_code ==
1869#ifdef _WIN32
1870 WSAENETUNREACH;
1871#else
1872 ENETUNREACH;
1873#endif
1874 if (size < 0 && unreachable && c->c2.tls_multi
1877 {
1878 msg(M_INFO, "Network unreachable, restarting");
1879 register_signal(c->sig, SIGUSR1, "network-unreachable");
1880 }
1881 }
1882 else
1883 {
1884 if (c->c2.to_link.len > 0)
1885 {
1886 msg(D_LINK_ERRORS, "TCP/UDP packet too large on write to %s (tried=%d,max=%d)",
1889 }
1890 }
1891
1892 buf_reset(&c->c2.to_link);
1893
1894 gc_free(&gc);
1895}
1896
1897/*
1898 * Input: c->c2.to_tun
1899 */
1900
1901void
1902process_outgoing_tun(struct context *c, struct link_socket *in_sock)
1903{
1904 /*
1905 * Set up for write() call to TUN/TAP
1906 * device.
1907 */
1908 if (c->c2.to_tun.len <= 0)
1909 {
1910 return;
1911 }
1912
1913 /*
1914 * The --mssfix option requires
1915 * us to examine the IP header (IPv4 or IPv6).
1916 */
1918 &c->c2.to_tun, in_sock);
1919
1920 if (c->c2.to_tun.len <= c->c2.frame.buf.payload_size)
1921 {
1922 /*
1923 * Write to TUN/TAP device.
1924 */
1925 ssize_t size;
1926
1927#ifdef LOG_RW
1928 if (c->c2.log_rw)
1929 {
1930 fprintf(stderr, "w");
1931 }
1932#endif
1933 dmsg(D_TUN_RW, "TUN WRITE [%d]", BLEN(&c->c2.to_tun));
1934
1935#ifdef PACKET_TRUNCATION_CHECK
1936 ipv4_packet_size_verify(BPTR(&c->c2.to_tun), BLEN(&c->c2.to_tun), TUNNEL_TYPE(c->c1.tuntap),
1937 "WRITE_TUN", &c->c2.n_trunc_tun_write);
1938#endif
1939
1940#ifdef _WIN32
1941 size = tun_write_win32(c->c1.tuntap, &c->c2.to_tun);
1942#else
1944 {
1945 size = write_tun_afunix(c->c1.tuntap, BPTR(&c->c2.to_tun), BLEN(&c->c2.to_tun));
1946 }
1947 else
1948 {
1949 size = write_tun(c->c1.tuntap, BPTR(&c->c2.to_tun), BLEN(&c->c2.to_tun));
1950 }
1951#endif
1952
1953 if (size > 0)
1954 {
1955 c->c2.tun_write_bytes += size;
1956 }
1957 check_status(size, "write to TUN/TAP", NULL, c->c1.tuntap);
1958
1959 /* check written packet size */
1960 if (size > 0)
1961 {
1962 /* Did we write a different size packet than we intended? */
1963 if (size != BLEN(&c->c2.to_tun))
1964 {
1966 "TUN/TAP packet was destructively fragmented on write to %s (tried=%d,actual=%zd)",
1967 c->c1.tuntap->actual_name, BLEN(&c->c2.to_tun), size);
1968 }
1969
1970 /* indicate activity regarding --inactive parameter */
1971 register_activity(c, size);
1972 }
1973 }
1974 else
1975 {
1976 /*
1977 * This should never happen, probably indicates some kind
1978 * of MTU mismatch.
1979 */
1980 msg(D_LINK_ERRORS, "tun packet too large on write (tried=%d,max=%d)", c->c2.to_tun.len,
1982 }
1983
1984 buf_reset(&c->c2.to_tun);
1985}
1986
1987void
1989{
1990 /* make sure current time (now) is updated on function entry */
1991
1992 /*
1993 * Start with an effectively infinite timeout, then let it
1994 * reduce to a timeout that reflects the component which
1995 * needs the earliest service.
1996 */
1997 c->c2.timeval.tv_sec = BIG_TIMEOUT;
1998 c->c2.timeval.tv_usec = 0;
1999
2000#if defined(_WIN32)
2002 {
2003 c->c2.timeval.tv_sec = 1;
2004 if (tuntap_defined(c->c1.tuntap))
2005 {
2007 }
2008 }
2009#endif
2010
2011 /* check coarse timers? */
2013 if (c->sig->signal_received)
2014 {
2015 return;
2016 }
2017
2018 /* If tls is enabled, do tls control channel packet processing. */
2019 if (c->c2.tls_multi)
2020 {
2021 check_tls(c);
2022 }
2023
2024 /* In certain cases, TLS errors will require a restart */
2026 if (c->sig->signal_received)
2027 {
2028 return;
2029 }
2030
2031 /* check for incoming control messages on the control channel like
2032 * push request/reply/update, or authentication failure and 2FA messages */
2033 if (tls_test_payload_len(c->c2.tls_multi) > 0)
2034 {
2036 }
2037
2038 /* Should we send an OCC message? */
2040
2041#ifdef ENABLE_FRAGMENT
2042 /* Should we deliver a datagram fragment to remote? */
2043 if (c->c2.fragment)
2044 {
2045 check_fragment(c);
2046 }
2047#endif
2048
2049 /* Update random component of timeout */
2051}
2052
2053void
2054multi_io_process_flags(struct context *c, struct event_set *es, struct link_socket *sock, const unsigned int flags)
2055{
2056 unsigned int socket = 0;
2057 unsigned int tuntap = 0;
2058 static uintptr_t tun_shift = TUN_SHIFT;
2059
2060 /*
2061 * Calculate the flags based on the provided 'flags' argument.
2062 */
2063 if ((c->options.mode != MODE_SERVER) && (flags & IOW_WAIT_SIGNAL))
2064 {
2065 static uintptr_t err_shift = ERR_SHIFT;
2066 wait_signal(es, (void *)err_shift);
2067 }
2068
2069 if (flags & IOW_TO_LINK)
2070 {
2071 if (flags & IOW_SHAPER)
2072 {
2073 /*
2074 * If sending this packet would put us over our traffic shaping
2075 * quota, don't send -- instead compute the delay we must wait
2076 * until it will be OK to send the packet.
2077 */
2078 int delay = 0;
2079
2080 /* set traffic shaping delay in microseconds */
2081 if (c->options.shaper)
2082 {
2083 delay = max_int(delay, shaper_delay(&c->c2.shaper));
2084 }
2085
2086 if (delay < 1000)
2087 {
2088 socket |= EVENT_WRITE;
2089 }
2090 else
2091 {
2092 shaper_soonest_event(&c->c2.timeval, delay);
2093 }
2094 }
2095 else
2096 {
2097 socket |= EVENT_WRITE;
2098 }
2099 }
2100 else if (!((flags & IOW_FRAG) && TO_LINK_FRAG(c)))
2101 {
2102 if (flags & IOW_READ_TUN)
2103 {
2104 tuntap |= EVENT_READ;
2105 }
2106 }
2107
2108 /*
2109 * If outgoing data (for TUN/TAP device) pending, wait for ready-to-send status
2110 * from device. Otherwise, wait for incoming data on TCP/UDP port.
2111 */
2112 if (flags & IOW_TO_TUN)
2113 {
2115 }
2116 else
2117 {
2118 if (flags & IOW_READ_LINK)
2119 {
2120 socket |= EVENT_READ;
2121 }
2122 }
2123
2124 /*
2125 * Force wait on TUN input, even if also waiting on TCP/UDP output
2126 */
2127 if (flags & IOW_READ_TUN_FORCE)
2128 {
2129 tuntap |= EVENT_READ;
2130 }
2131
2132 /*
2133 * Configure event wait based on socket, tuntap flags.
2134 * (for TCP server sockets this happens in
2135 * socket_set_listen_persistent()).
2136 */
2137 socket_set(sock, es, socket, &sock->ev_arg, NULL);
2138 tun_set(c->c1.tuntap, es, tuntap, (void *)tun_shift, NULL);
2139}
2140
2141/*
2142 * This is the core I/O wait function, used for all I/O waits.
2143 *
2144 * Invoked by P2P instances in tunnel_point_to_point() or by P2MP
2145 * instances within the per-client context in multi_io.c.
2146 */
2147void
2148io_wait(struct context *c, const unsigned int flags)
2149{
2150 struct event_set_return esr[4];
2151
2152 /* These shifts all depend on EVENT_READ and EVENT_WRITE */
2153 static uintptr_t socket_shift = SOCKET_SHIFT; /* depends on SOCKET_READ and SOCKET_WRITE */
2154#ifdef ENABLE_MANAGEMENT
2155 static uintptr_t management_shift =
2156 MANAGEMENT_SHIFT; /* depends on MANAGEMENT_READ and MANAGEMENT_WRITE */
2157#endif
2158
2159#if defined(TARGET_LINUX) || defined(TARGET_FREEBSD)
2160 static uintptr_t dco_shift = DCO_SHIFT; /* Event from DCO linux kernel module */
2161#endif
2162
2163 /*
2164 * Decide what kind of events we want to wait for.
2165 */
2167
2168 multi_io_process_flags(c, c->c2.event_set, c->c2.link_sockets[0], flags);
2169
2170#if defined(TARGET_LINUX) || defined(TARGET_FREEBSD)
2171 if (c->c1.tuntap)
2172 {
2173 dco_event_set(&c->c1.tuntap->dco, c->c2.event_set, (void *)dco_shift);
2174 }
2175#endif
2176
2177#ifdef ENABLE_MANAGEMENT
2178 if (management)
2179 {
2180 management_socket_set(management, c->c2.event_set, (void *)management_shift, NULL);
2181 }
2182#endif
2183
2184 /*
2185 * Possible scenarios:
2186 * (1) tcp/udp port has data available to read
2187 * (2) tcp/udp port is ready to accept more data to write
2188 * (3) tun dev has data available to read
2189 * (4) tun dev is ready to accept more data to write
2190 * (5) we received a signal (handler sets signal_received)
2191 * (6) timeout (tv) expired
2192 */
2193
2195
2196 if (!c->sig->signal_received)
2197 {
2198 if (!(flags & IOW_CHECK_RESIDUAL) || !sockets_read_residual(c))
2199 {
2200 int status;
2201
2202#ifndef ENABLE_SMALL
2204 {
2206 }
2207#endif
2208
2209 /*
2210 * Wait for something to happen.
2211 */
2212 status = event_wait(c->c2.event_set, &c->c2.timeval, esr, SIZE(esr));
2213
2214 check_status(status, "event_wait", NULL, NULL);
2215
2216 if (status > 0)
2217 {
2218 int i;
2219 c->c2.event_set_status = 0;
2220 for (i = 0; i < status; ++i)
2221 {
2222 const struct event_set_return *e = &esr[i];
2223 uintptr_t shift;
2224
2225 if (e->arg >= MULTI_N)
2226 {
2227 const struct event_arg *ev_arg = (struct event_arg *)e->arg;
2228 if (ev_arg->type != EVENT_ARG_LINK_SOCKET)
2229 {
2231 msg(D_LINK_ERRORS, "io_work: non socket event delivered");
2232 return;
2233 }
2234
2235 shift = socket_shift;
2236 }
2237 else
2238 {
2239 shift = (uintptr_t)e->arg;
2240 }
2241
2242 c->c2.event_set_status |= ((e->rwflags & 3) << shift);
2243 }
2244 }
2245 else if (status == 0)
2246 {
2248 }
2249 }
2250 else
2251 {
2253 }
2254 }
2255
2256 /* 'now' should always be a reasonably up-to-date timestamp */
2257 update_time();
2258
2259 /* set signal_received if a signal was received */
2260 if (c->c2.event_set_status & ES_ERROR)
2261 {
2263 }
2264
2265 dmsg(D_EVENT_WAIT, "I/O WAIT status=0x%04x", c->c2.event_set_status);
2266}
2267
2268void
2270{
2271 const unsigned int status = c->c2.event_set_status;
2272
2273#ifdef ENABLE_MANAGEMENT
2275 {
2278 }
2279#endif
2280
2281 /* TCP/UDP port ready to accept write */
2282 if (status & SOCKET_WRITE)
2283 {
2285 }
2286 /* TUN device ready to accept write */
2287 else if (status & TUN_WRITE)
2288 {
2290 }
2291 /* Incoming data on TCP/UDP port */
2292 else if (status & SOCKET_READ)
2293 {
2295 if (!IS_SIG(c))
2296 {
2298 }
2299 }
2300 /* Incoming data on TUN device */
2301 else if (status & TUN_READ)
2302 {
2304 if (!IS_SIG(c))
2305 {
2307 }
2308 }
2309 else if (status & DCO_READ)
2310 {
2311 if (!IS_SIG(c))
2312 {
2314 }
2315 }
2316}
void check_send_auth_token(struct context *c)
Checks if the timer to resend the auth-token has expired and if a new auth-token should be send to th...
Definition auth_token.c:436
bool buf_printf(struct buffer *buf, const char *format,...)
printf-style append to a buffer with overflow check.
Definition buffer.c:226
bool buf_assign(struct buffer *dest, const struct buffer *src)
Assign the content of one buffer to another.
Definition buffer.c:159
struct buffer alloc_buf_gc(size_t size, struct gc_arena *gc)
Allocate a buffer of the given size under garbage collection.
Definition buffer.c:77
bool buf_string_match_head_str(const struct buffer *src, const char *match)
Return true if the head of src matches the string match.
Definition buffer.c:728
#define BSTR(buf)
Return the buffer content pointer cast to char *.
Definition buffer.h:157
#define BPTR(buf)
Return a pointer to the start of the buffer content.
Definition buffer.h:139
static bool buf_write_prepend(struct buffer *dest, const void *src, int size)
Prepend data to a buffer.
Definition buffer.h:1286
static bool buf_copy_n(struct buffer *dest, struct buffer *src, int n)
Read n bytes from src and append them to dest.
Definition buffer.h:1383
static void buf_reset(struct buffer *buf)
Reset a buffer to an undefined (unallocated) state.
Definition buffer.h:599
static bool buf_safe(const struct buffer *buf, size_t len)
Check whether len bytes can be appended to a buffer.
Definition buffer.h:1017
#define CBPTR(buf)
Return a const pointer to the start of the buffer content.
Definition buffer.h:141
static bool buf_advance(struct buffer *buf, ssize_t size)
Advance the content start of a buffer, consuming bytes from the front.
Definition buffer.h:1188
#define BLEN(buf)
Return the length of the buffer content in bytes.
Definition buffer.h:151
#define BLENZ(buf)
Return the length of the buffer content as a size_t.
Definition buffer.h:153
static void gc_free(struct gc_arena *a)
Free all allocations in a garbage collection arena.
Definition buffer.h:1976
#define CBSTR(buf)
Return the buffer content pointer cast to const char *.
Definition buffer.h:159
#define buf_init(buf, offset)
Definition buffer.h:364
static struct gc_arena gc_new(void)
Allocate and return a new, empty garbage collection arena.
Definition buffer.h:1960
void client_nat_transform(const struct client_nat_option_list *list, struct buffer *ipbuf, const int direction)
Definition clinat.c:183
#define CN_INCOMING
Definition clinat.h:31
#define CN_OUTGOING
Definition clinat.h:30
uint64_t counter_type
Definition common.h:31
int interval_t
Definition common.h:37
#define PUSH_REQUEST_INTERVAL
Definition common.h:94
#define BIG_TIMEOUT
Definition common.h:42
int64_t get_random(void)
an analogue to the random() function, but use prng_bytes and also int64_t instead of long to avoid LL...
Definition crypto.c:1735
static void dco_event_set(dco_context_t *dco, struct event_set *es, void *arg)
Definition dco.h:316
static void dco_delete_iroutes(openvpn_net_ctx_t *net_ctx, const struct context *c)
Definition dco.h:364
static int dco_read_and_process(dco_context_t *dco)
Definition dco.h:309
static bool dco_update_keys(dco_context_t *dco, struct tls_multi *multi)
Definition dco.h:328
void * dco_context_t
Definition dco.h:259
static int dco_get_peer_stats(struct context *c, const bool raise_sigusr1_on_err)
Definition dco.h:375
in_addr_t dhcp_extract_router_msg(struct buffer *ipbuf)
Definition dhcp.c:148
#define D_TUN_RW
Definition errlevel.h:113
#define D_TAP_WIN_DEBUG
Definition errlevel.h:114
#define D_PING
Definition errlevel.h:143
#define D_EVENT_WAIT
Definition errlevel.h:161
#define D_INTERVAL
Definition errlevel.h:157
#define D_STREAM_ERRORS
Definition errlevel.h:62
#define D_DCO_DEBUG
Definition errlevel.h:117
#define D_PUSH_ERRORS
Definition errlevel.h:66
#define D_LOW
Definition errlevel.h:96
#define M_INFO
Definition errlevel.h:54
#define D_SCHED_EXIT
Definition errlevel.h:88
#define D_ROUTE
Definition errlevel.h:79
#define D_LINK_ERRORS
Definition errlevel.h:56
#define D_LINK_RW
Definition errlevel.h:112
#define DCO_READ
Definition event.h:72
#define MANAGEMENT_SHIFT
Definition event.h:68
#define SOCKET_SHIFT
Definition event.h:59
#define TUN_WRITE
Definition event.h:64
#define SOCKET_READ
Definition event.h:60
#define MANAGEMENT_READ
Definition event.h:69
#define MANAGEMENT_WRITE
Definition event.h:70
static int event_wait(struct event_set *es, const struct timeval *tv, struct event_set_return *out, int outlen)
Definition event.h:186
#define ES_ERROR
Definition event.h:66
#define SOCKET_WRITE
Definition event.h:61
#define ES_TIMEOUT
Definition event.h:67
#define EVENT_WRITE
Definition event.h:38
#define MULTI_N
Definition event.h:85
#define TUN_SHIFT
Definition event.h:62
#define EVENT_READ
Definition event.h:37
#define TUN_READ
Definition event.h:63
static void event_reset(struct event_set *es)
Definition event.h:168
static void wait_signal(struct event_set *es, void *arg)
Definition event.h:196
#define DCO_SHIFT
Definition event.h:71
#define ERR_SHIFT
Definition event.h:65
@ EVENT_ARG_LINK_SOCKET
Definition event.h:135
void process_incoming_dco(dco_context_t *dco)
Process an incoming DCO message (from kernel space).
Definition forward.c:1268
counter_type link_write_bytes_global
Definition forward.c:49
static void check_inactivity_timeout(struct context *c)
Definition forward.c:486
void reschedule_multi_process(struct context *c)
Reschedule tls_multi_process.
Definition forward.c:397
int get_server_poll_remaining_time(struct event_timeout *server_poll_timeout)
Definition forward.c:510
bool send_control_channel_string(struct context *c, const char *str, msglvl_t msglevel)
Definition forward.c:404
static void context_reschedule_sec(struct context *c, time_t sec)
Definition forward.c:131
static void check_fragment(struct context *c)
Definition forward.c:595
static void check_tls_errors(struct context *c)
Definition forward.c:98
static void check_scheduled_exit(struct context *c)
Definition forward.c:572
#define MAX_ICMPV6LEN
static void check_session_timeout(struct context *c)
Definition forward.c:731
void process_io(struct context *c, struct link_socket *sock)
Definition forward.c:2269
static void show_wait_status(struct context *c)
Definition forward.c:71
static void check_timeout_random_component(struct context *c)
Definition forward.c:893
bool schedule_exit(struct context *c)
Definition forward.c:534
static void process_coarse_timers(struct context *c)
Definition forward.c:745
static void check_connection_established(struct context *c)
Definition forward.c:339
static void check_timeout_random_component_dowork(struct context *c)
Definition forward.c:882
static const char * wait_status_string(struct context *c, struct gc_arena *gc)
Definition forward.c:56
static void buffer_turnover(const uint8_t *orig_buf, struct buffer *dest_stub, struct buffer *src_stub, struct buffer *storage)
Definition forward.c:624
static void check_tls_errors_nco(struct context *c)
Definition forward.c:88
void ipv6_send_icmp_unreachable(struct context *c, struct buffer *buf, bool client)
Forges a IPv6 ICMP packet with a no route to host error code from the IPv6 packet in buf and sends it...
Definition forward.c:1558
bool send_control_channel_string_dowork(struct tls_session *session, const char *str, msglvl_t msglevel)
Definition forward.c:376
void pre_select(struct context *c)
Definition forward.c:1988
static void check_incoming_control_channel(struct context *c)
Definition forward.c:289
static void check_add_routes(struct context *c)
Definition forward.c:436
static void check_server_poll_timeout(struct context *c)
Definition forward.c:518
static void parse_incoming_control_channel_command(struct context *c, struct buffer *buf)
Definition forward.c:240
static void socks_postprocess_incoming_link(struct context *c, struct link_socket *sock)
Definition forward.c:911
static void check_push_request(struct context *c)
Definition forward.c:321
static void process_incoming_link(struct context *c, struct link_socket *sock)
Definition forward.c:1224
static void check_tls_errors_co(struct context *c)
Definition forward.c:81
static void socks_preprocess_outgoing_link(struct context *c, struct link_socket *sock, struct link_socket_actual **to_addr, int *size_delta)
Definition forward.c:920
void io_wait(struct context *c, const unsigned int flags)
Definition forward.c:2148
static void link_socket_write_post_size_adjust(int *size, int size_delta, struct buffer *buf)
Definition forward.c:932
static void context_immediate_reschedule(struct context *c)
Definition forward.c:124
static void check_add_routes_action(struct context *c, const bool errors)
Definition forward.c:421
static void drop_if_recursive_routing(struct context *c, struct buffer *buf)
Drops UDP packets which OS decided to route via tun.
Definition forward.c:1385
counter_type link_read_bytes_global
Definition forward.c:48
static void check_coarse_timers(struct context *c)
Definition forward.c:857
void multi_io_process_flags(struct context *c, struct event_set *es, struct link_socket *sock, const unsigned int flags)
Processes I/O flags to configure socket and TUN/TAP event monitors.
Definition forward.c:2054
void check_dco_key_status(struct context *c)
Definition forward.c:145
void process_ip_header(struct context *c, unsigned int flags, struct buffer *buf, struct link_socket *sock)
Definition forward.c:1685
void extract_dco_float_peer_addr(const sa_family_t socket_family, struct openvpn_sockaddr *out_osaddr, const struct sockaddr *float_sa)
Transfers float_sa data extracted from an incoming DCO PEER_FLOAT_NTF to out_osaddr for later process...
Definition forward.c:1234
static void check_tls(struct context *c)
Definition forward.c:178
static void check_status_file(struct context *c)
Definition forward.c:581
Interface functions to the internal and external multiplexers.
#define PIP_MSSFIX
Definition forward.h:337
#define PIPV4_CLIENT_NAT
Definition forward.h:340
static void register_activity(struct context *c, const int64_t size)
Definition forward.h:364
#define IOW_WAIT_SIGNAL
Definition forward.h:62
#define IOW_READ_TUN
Definition forward.h:56
#define PIPV4_EXTRACT_DHCP_ROUTER
Definition forward.h:339
#define PIPV6_ICMP_NOHOST_SERVER
Definition forward.h:342
#define PIPV6_ICMP_NOHOST_CLIENT
Definition forward.h:341
#define IOW_SHAPER
Definition forward.h:58
#define IOW_FRAG
Definition forward.h:60
static struct link_socket_info * get_link_socket_info(struct context *c)
Definition forward.h:351
#define IOW_READ_LINK
Definition forward.h:57
#define IOW_CHECK_RESIDUAL
Definition forward.h:59
#define TO_LINK_FRAG(c)
Definition forward.h:42
static bool connection_established(struct context *c)
Definition forward.h:398
#define IOW_TO_TUN
Definition forward.h:54
#define PIPV4_PASSTOS
Definition forward.h:336
#define IOW_READ_TUN_FORCE
Definition forward.h:61
#define PIP_OUTGOING
Definition forward.h:338
#define IOW_TO_LINK
Definition forward.h:55
#define KS_PRIMARY
Primary key state index.
Definition ssl_common.h:464
#define TM_ACTIVE
Active tls_session.
Definition ssl_common.h:544
void encrypt_sign(struct context *c, bool comp_frag)
Process a data channel packet that will be sent through a VPN tunnel.
Definition forward.c:644
void tls_post_encrypt(struct tls_multi *multi, struct buffer *buf)
Perform some accounting for the key state used.
Definition ssl.c:4196
void openvpn_encrypt(struct buffer *buf, struct buffer work, struct crypto_options *opt)
Encrypt and HMAC sign a packet so that it can be sent as a data channel VPN tunnel packet to a remote...
Definition crypto.c:329
void tls_prepend_opcode_v1(const struct tls_multi *multi, struct buffer *buf)
Prepend a one-byte OpenVPN data channel P_DATA_V1 opcode to the packet.
Definition ssl.c:4168
void tls_pre_encrypt(struct tls_multi *multi, struct buffer *buf, struct crypto_options **opt)
Choose the appropriate security parameters with which to process an outgoing packet.
Definition ssl.c:4136
void tls_prepend_opcode_v2(const struct tls_multi *multi, struct buffer *buf)
Prepend an OpenVPN data channel P_DATA_V2 header to the packet.
Definition ssl.c:4182
bool openvpn_decrypt(struct buffer *buf, struct buffer work, struct crypto_options *opt, const struct frame *frame, const uint8_t *ad_start)
HMAC verify and decrypt a data channel packet received from a remote OpenVPN peer.
Definition crypto.c:779
bool process_incoming_link_part1(struct context *c, struct link_socket_info *lsi, bool floated)
Starts processing a packet read from the external network interface.
Definition forward.c:1008
void process_incoming_link_part2(struct context *c, struct link_socket_info *lsi, const uint8_t *orig_buf)
Continues processing a packet read from the external network interface.
Definition forward.c:1141
void process_outgoing_link(struct context *c, struct link_socket *sock)
Write a packet to the external network interface.
Definition forward.c:1769
void read_incoming_link(struct context *c, struct link_socket *sock)
Read a packet from the external network interface.
Definition forward.c:949
bool tls_pre_decrypt(struct tls_multi *multi, const struct link_socket_actual *from, struct buffer *buf, struct crypto_options **opt, bool floated, const uint8_t **ad_start)
Determine whether an incoming packet is a data channel or control channel packet, and process accordi...
Definition ssl.c:3744
static void fragment_housekeeping(struct fragment_master *f, struct frame *frame, struct timeval *tv)
Perform housekeeping of a fragment_master structure.
Definition fragment.h:456
static bool fragment_outgoing_defined(struct fragment_master *f)
Check whether a fragment_master structure contains fragments ready to be sent.
Definition fragment.h:428
void fragment_outgoing(struct fragment_master *f, struct buffer *buf, const struct frame *frame)
Process an outgoing packet, which may or may not need to be fragmented.
Definition fragment.c:313
void fragment_incoming(struct fragment_master *f, struct buffer *buf, const struct frame *frame)
Process an incoming packet, which may or may not be fragmented.
Definition fragment.c:139
bool fragment_ready_to_send(struct fragment_master *f, struct buffer *buf, const struct frame *frame)
Check whether outgoing fragments are ready to be send, and if so make one available.
Definition fragment.c:363
void read_incoming_tun(struct context *c)
Read a packet from the virtual tun/tap network interface.
Definition forward.c:1321
void process_incoming_tun(struct context *c, struct link_socket *out_sock)
Process a packet read from the virtual tun/tap network interface.
Definition forward.c:1500
void process_outgoing_tun(struct context *c, struct link_socket *in_sock)
Write a packet to the virtual tun/tap network interface.
Definition forward.c:1902
void initialization_sequence_completed(struct context *c, const unsigned int flags)
Definition init.c:1514
void reset_coarse_timers(struct context *c)
Definition init.c:1282
bool do_up(struct context *c, bool pulled_options, uint64_t option_types_found)
Definition init.c:2324
bool do_route(const struct options *options, struct route_list *route_list, struct route_ipv6_list *route_ipv6_list, const struct tuntap *tt, const struct plugin_list *plugins, struct env_set *es, openvpn_net_ctx_t *ctx)
Definition init.c:1635
#define ISC_ERRORS
Definition init.h:120
#define ISC_ROUTE_ERRORS
Definition init.h:122
static int min_int(int x, int y)
Definition integer.h:105
static int max_int(int x, int y)
Definition integer.h:92
static SERVICE_STATUS status
Definition interactive.c:52
bool event_timeout_trigger(struct event_timeout *et, struct timeval *tv, const int et_const_retry)
This is the principal function for testing and triggering recurring timers.
Definition interval.c:42
#define ETT_DEFAULT
Definition interval.h:222
static void interval_future_trigger(struct interval *top, interval_t wakeup)
Definition interval.h:106
static void event_timeout_reset(struct event_timeout *et)
Resets a timer.
Definition interval.h:187
static void interval_action(struct interval *top)
Definition interval.h:122
static bool event_timeout_defined(const struct event_timeout *et)
Definition interval.h:142
static void event_timeout_init(struct event_timeout *et, interval_t n, const time_t last)
Initialises a timer struct.
Definition interval.h:172
static void event_timeout_clear(struct event_timeout *et)
Clears the timeout and reset all values to 0.
Definition interval.h:153
static void interval_schedule_wakeup(struct interval *top, interval_t *wakeup)
Definition interval.h:92
static void event_timeout_modify_wakeup(struct event_timeout *et, interval_t n)
Sets the interval n of a timeout.
Definition interval.h:204
static bool interval_test(struct interval *top)
Definition interval.h:65
static interval_t event_timeout_remaining(struct event_timeout *et)
Returns the time until the timeout should triggered, from now.
Definition interval.h:217
void management_socket_set(struct management *man, struct event_set *es, void *arg, unsigned int *persistent)
Definition manage.c:3246
void management_set_state(struct management *man, const int state, const char *detail, const in_addr_t *tun_local_ip, const struct in6_addr *tun_local_ip6, const struct openvpn_sockaddr *local, const struct openvpn_sockaddr *remote)
Definition manage.c:2881
void management_io(struct management *man)
Definition manage.c:3284
void management_check_bytecount_client(struct context *c, struct management *man, struct timeval *timeval)
Definition manage.c:4260
void management_sleep(const int n)
A sleep function that services the management layer for n seconds rather than doing nothing.
Definition manage.c:4236
#define OPENVPN_STATE_GET_CONFIG
Definition manage.h:461
const char * sanitize_control_message(const char *src, struct gc_arena *gc)
Definition misc.c:662
void mss_fixup_ipv6(struct buffer *buf, uint16_t maxmss)
Definition mss.c:83
void mss_fixup_ipv4(struct buffer *buf, uint16_t maxmss)
Definition mss.c:46
void frame_adjust_path_mtu(struct context *c)
Checks and adjusts the fragment and mssfix value according to the discovered path mtu value.
Definition mss.c:336
void process_received_occ_msg(struct context *c)
Definition occ.c:360
static void check_send_occ_msg(struct context *c)
Definition occ.h:138
static bool is_occ_msg(const struct buffer *buf)
Definition occ.h:83
static void check_send_occ_req(struct context *c)
Definition occ.h:110
static void check_send_occ_load_test(struct context *c)
Definition occ.h:124
#define CLEAR(x)
Definition basic.h:32
#define SIZE(x)
Definition basic.h:29
static bool check_debug_level(msglvl_t level)
Definition error.h:253
#define M_NOPREFIX
Definition error.h:98
static void check_status(ssize_t status, const char *description, struct link_socket *sock, struct tuntap *tt)
Definition error.h:310
#define dmsg(flags,...)
Definition error.h:164
#define openvpn_errno()
Definition error.h:71
#define msg(flags,...)
Definition error.h:152
unsigned int msglvl_t
Definition error.h:77
#define ASSERT(x)
Definition error.h:221
#define M_WARN
Definition error.h:92
#define TLS_MODE(c)
Definition openvpn.h:541
#define PROTO_DUMP(buf, gc)
Definition openvpn.h:543
#define MODE_POINT_TO_POINT
Definition options.h:264
#define MODE_SERVER
Definition options.h:265
static bool dco_enabled(const struct options *o)
Returns whether the current configuration has dco enabled.
Definition options.h:971
time_t now
Definition otime.c:33
const char * tv_string(const struct timeval *tv, struct gc_arena *gc)
Definition otime.c:83
static void update_time(void)
Definition otime.h:84
long tv_sec_t
Definition otime.h:31
static void tv_add(struct timeval *dest, const struct timeval *src)
Definition otime.h:129
@ OVPN_DEL_PEER_REASON_EXPIRED
@ OVPN_CMD_SWAP_KEYS
@ OVPN_CMD_DEL_PEER
void packet_id_persist_save(struct packet_id_persist *p)
Definition packet_id.c:506
static bool packet_id_persist_enabled(const struct packet_id_persist *p)
Definition packet_id.h:278
void trigger_ping_timeout_signal(struct context *c)
Trigger the correct signal on a –ping timeout depending if –ping-exit is set (SIGTERM) or not (SIGUSR...
Definition ping.c:45
static void check_ping_restart(struct context *c)
Definition ping.h:59
static bool is_ping_msg(const struct buffer *buf)
Definition ping.h:40
static void check_ping_send(struct context *c)
Definition ping.h:76
bool is_ipv4(int tunnel_type, struct buffer *buf)
Definition proto.c:107
bool is_ipv6(int tunnel_type, struct buffer *buf)
Definition proto.c:112
uint16_t ip_checksum(const sa_family_t af, const uint8_t *payload, const int len_payload, const uint8_t *src_addr, const uint8_t *dest_addr, const int proto)
Calculates an IP or IPv6 checksum with a pseudo header as required by TCP, UDP and ICMPv6.
Definition proto.c:119
#define OPENVPN_IPH_GET_LEN(v)
Definition proto.h:92
static int get_tun_ip_ver(int tunnel_type, struct buffer *buf, int *ip_hdr_offset)
Definition proto.h:251
#define DEV_TYPE_TAP
Definition proto.h:36
#define OPENVPN_ETH_ALEN
Definition proto.h:52
#define OPENVPN_ETH_P_IPV6
Definition proto.h:59
#define OPENVPN_IPPROTO_ICMPV6
Definition proto.h:107
#define OPENVPN_IN6_ARE_ADDR_EQUAL(a, b)
Version of IN6_ARE_ADDR_EQUAL that is guaranteed to work for unaligned access.
Definition proto.h:87
#define OPENVPN_IPPROTO_UDP
Definition proto.h:106
#define OPENVPN_ICMP6_DESTINATION_UNREACHABLE
Definition proto.h:136
#define OPENVPN_IPPROTO_TCP
Definition proto.h:105
#define OPENVPN_ICMP6_DU_NOROUTE
Definition proto.h:144
void receive_auth_pending(struct context *c, const struct buffer *buffer)
Parses an AUTH_PENDING message and if in pull mode extends the timeout.
Definition push.c:336
void receive_auth_failed(struct context *c, const struct buffer *buffer)
Definition push.c:48
void server_pushed_signal(struct context *c, const struct buffer *buffer, const bool restart, const int adv)
Definition push.c:128
void receive_cr_response(struct context *c, const struct buffer *buffer)
Definition push.c:263
void send_auth_failed(struct context *c, const char *client_reason)
Definition push.c:393
void receive_exit_message(struct context *c)
Definition push.c:189
bool send_push_request(struct context *c)
Definition push.c:571
void incoming_push_message(struct context *c, const struct buffer *buffer)
Definition push.c:505
void server_pushed_info(const struct buffer *buffer, const int adv)
Definition push.c:225
bool test_routes(const struct route_list *rl, const struct tuntap *tt)
Definition route.c:2404
void route_list_add_vpn_gateway(struct route_list *rl, struct env_set *es, const in_addr_t addr)
Definition route.c:524
void show_routes(msglvl_t msglevel)
Definition route.c:3029
bool shaper_soonest_event(struct timeval *tv, int delay)
Definition shaper.c:36
static void shaper_wrote_bytes(struct shaper *s, int nbytes)
Definition shaper.h:121
static int shaper_delay(struct shaper *s)
Definition shaper.h:96
void print_status(struct context *c, struct status_output *so)
Definition sig.c:478
void process_explicit_exit_notification_timer_wakeup(struct context *c)
Definition sig.c:563
void register_signal(struct signal_info *si, int signum, const char *signal_text)
Register a soft signal in the signal_info struct si respecting priority.
Definition sig.c:228
#define IS_SIG(c)
Definition sig.h:47
static void get_signal(volatile int *sig)
Copy the global signal_received (if non-zero) to the passed-in argument sig.
Definition sig.h:109
const char * socket_stat(const struct link_socket *s, unsigned int rwflags, struct gc_arena *gc)
Definition socket.c:2029
int sockethandle_finalize(sockethandle_t sh, struct overlapped_io *io, struct buffer *buf, struct link_socket_actual *from)
Definition socket.c:2860
unsigned int socket_set(struct link_socket *s, struct event_set *es, unsigned int rwflags, void *arg, unsigned int *persistent)
Definition socket.c:2953
void link_socket_bad_incoming_addr(struct buffer *buf, const struct link_socket_info *info, const struct link_socket_actual *from_addr)
Definition socket.c:1929
bool sockets_read_residual(const struct context *c)
Definition socket.c:45
static ssize_t link_socket_read(struct link_socket *sock, struct buffer *buf, struct link_socket_actual *from)
Definition socket.h:630
static bool socket_connection_reset(const struct link_socket *sock, ssize_t status)
Definition socket.h:476
static ssize_t link_socket_write(struct link_socket *sock, struct buffer *buf, struct link_socket_actual *to)
Definition socket.h:749
static bool link_socket_connection_oriented(const struct link_socket *sock)
Definition socket.h:441
static bool link_socket_verify_incoming_addr(struct buffer *buf, const struct link_socket_info *info, const struct link_socket_actual *from_addr)
Definition socket.h:499
static void link_socket_set_outgoing_addr(struct link_socket_info *info, const struct link_socket_actual *act, const char *common_name, struct env_set *es)
Definition socket.h:546
static void link_socket_get_outgoing_addr(struct buffer *buf, const struct link_socket_info *info, struct link_socket_actual **act)
Definition socket.h:526
const char * proto2ascii(int proto, sa_family_t af, bool display_form)
const char * print_link_socket_actual(const struct link_socket_actual *act, struct gc_arena *gc)
const char * print_in6_addr(struct in6_addr a6, unsigned int flags, struct gc_arena *gc)
const char * print_in_addr_t(in_addr_t addr, unsigned int flags, struct gc_arena *gc)
static bool link_socket_actual_defined(const struct link_socket_actual *act)
static int datagram_overhead(sa_family_t af, int proto)
@ PROTO_UDP
@ PROTO_TCP
#define IA_NET_ORDER
Definition socket_util.h:90
int socks_process_outgoing_udp(struct buffer *buf, const struct link_socket_actual *to)
Definition socks.c:484
void socks_process_incoming_udp(struct buffer *buf, struct link_socket_actual *from)
Definition socks.c:446
bool tls_send_payload(struct key_state *ks, const uint8_t *data, size_t size)
Definition ssl.c:4216
bool tls_rec_payload(struct tls_multi *multi, struct buffer *buf)
Definition ssl.c:4249
void tls_session_soft_reset(struct tls_multi *tls_multi)
Definition ssl.c:1833
int tls_multi_process(struct tls_multi *multi, struct buffer *to_link, struct link_socket_actual **to_link_addr, struct link_socket_info *to_link_socket_info, interval_t *wakeup)
Definition ssl.c:3365
#define TLSMP_RECONNECT
Definition ssl.h:232
#define TLSMP_ACTIVE
Definition ssl.h:230
static bool tls_initial_packet_received(const struct tls_multi *multi)
Definition ssl.h:492
#define TLSMP_RESTART
the session cannot recover on its own and has to be restarted
Definition ssl.h:234
static void tls_set_single_session(struct tls_multi *multi)
Definition ssl.h:512
#define TLSMP_KILL
Definition ssl.h:231
static int tls_test_payload_len(const struct tls_multi *multi)
Definition ssl.h:498
@ CAS_CONNECT_DONE
Definition ssl_common.h:593
struct buffer extract_command_buffer(struct buffer *buf, struct gc_arena *gc)
Extracts a control channel message from buf and adjusts the size of buf after the message has been ex...
Definition ssl_pkt.c:556
#define P_DATA_V1
Definition ssl_pkt.h:47
#define P_OPCODE_SHIFT
Definition ssl_pkt.h:39
Control Channel Verification Module.
Wrapper structure for dynamically allocated memory.
Definition buffer.h:71
uint8_t * data
Pointer to the allocated memory.
Definition buffer.h:78
int len
Length in bytes of the actual content within the allocated memory.
Definition buffer.h:76
int mssfix
Definition options.h:146
int connect_timeout
Definition options.h:123
struct status_output * status_output
Definition openvpn.h:186
struct route_list * route_list
List of routing information.
Definition openvpn.h:178
int link_sockets_num
Definition openvpn.h:159
struct route_ipv6_list * route_ipv6_list
Definition openvpn.h:183
struct packet_id_persist pid_persist
Definition openvpn.h:171
struct tuntap * tuntap
Tun/tap virtual network interface.
Definition openvpn.h:173
counter_type link_read_bytes
Definition openvpn.h:267
counter_type link_write_bytes
Definition openvpn.h:270
struct event_timeout server_poll_interval
Definition openvpn.h:408
int max_recv_size_local
Definition openvpn.h:309
struct fragment_master * fragment
Definition openvpn.h:253
time_t update_timeout_random_component
Definition openvpn.h:403
unsigned int event_set_status
Definition openvpn.h:236
counter_type dco_read_bytes
Definition openvpn.h:268
struct event_timeout route_wakeup_expire
Definition openvpn.h:384
struct event_timeout ping_send_interval
Definition openvpn.h:284
int max_send_size_local
Definition openvpn.h:311
struct timeval timeout_random_component
Definition openvpn.h:404
counter_type tun_read_bytes
Definition openvpn.h:265
counter_type dco_write_bytes
Definition openvpn.h:271
struct event_timeout scheduled_exit
Definition openvpn.h:444
struct env_set * es
Definition openvpn.h:420
time_t push_request_timeout
Definition openvpn.h:437
struct interval tmp_int
Definition openvpn.h:344
struct event_timeout auth_token_renewal_interval
Definition openvpn.h:294
struct event_timeout wait_for_connect
Definition openvpn.h:283
struct shaper shaper
Definition openvpn.h:260
struct event_timeout push_request_interval
Definition openvpn.h:436
struct tls_multi * tls_multi
TLS state structure for this VPN tunnel.
Definition openvpn.h:324
time_t coarse_timer_wakeup
Definition openvpn.h:399
int scheduled_exit_signal
Definition openvpn.h:445
struct frame frame
Definition openvpn.h:249
struct link_socket_actual from
Definition openvpn.h:246
struct frame frame_fragment
Definition openvpn.h:254
struct buffer to_link
Definition openvpn.h:377
int64_t inactivity_bytes
Definition openvpn.h:289
struct crypto_options crypto_options
Security parameters and crypto state used by the Data Channel Crypto module to process data channel p...
Definition openvpn.h:349
struct buffer to_tun
Definition openvpn.h:376
counter_type tun_write_bytes
Definition openvpn.h:266
struct link_socket ** link_sockets
Definition openvpn.h:238
counter_type link_read_bytes_auth
Definition openvpn.h:269
struct event_timeout packet_id_persist_interval
Definition openvpn.h:355
struct link_socket_actual * to_link_addr
Definition openvpn.h:245
struct event_timeout session_interval
Definition openvpn.h:291
int original_recv_size
Definition openvpn.h:308
struct buffer buf
Definition openvpn.h:375
struct timeval timeval
Time to next event of timers and similar.
Definition openvpn.h:396
time_t explicit_exit_notification_time_wait
Definition openvpn.h:416
bool log_rw
Definition openvpn.h:380
struct event_set * event_set
Definition openvpn.h:231
struct context_buffers * buffers
Definition openvpn.h:367
struct event_timeout explicit_exit_notification_interval
Definition openvpn.h:417
struct event_timeout route_wakeup
Definition openvpn.h:383
int tls_exit_signal
Definition openvpn.h:347
struct event_timeout inactivity_interval
Definition openvpn.h:288
struct event_timeout ping_rec_interval
Definition openvpn.h:285
struct buffer read_link_buf
Definition openvpn.h:114
struct buffer encrypt_buf
Definition openvpn.h:101
struct buffer read_tun_buf
Definition openvpn.h:115
struct buffer decrypt_buf
Definition openvpn.h:102
struct buffer aux_buf
Definition openvpn.h:98
int restart_sleep_seconds
Definition openvpn.h:123
Contains all state information for one tunnel.
Definition openvpn.h:471
bool did_dco_iroutes
Whether DCO iroutes have been installed.
Definition openvpn.h:510
struct signal_info * sig
Internal error signaling object.
Definition openvpn.h:500
openvpn_net_ctx_t net_ctx
Networking API opaque context.
Definition openvpn.h:498
struct plugin_list * plugins
List of plug-ins.
Definition openvpn.h:502
struct context_2 c2
Level 2 context.
Definition openvpn.h:516
struct options options
Options loaded from command line or configuration file.
Definition openvpn.h:472
struct context_1 c1
Level 1 context.
Definition openvpn.h:515
struct context_persist persist
Persistent context.
Definition openvpn.h:512
Security parameter state for processing data channel packets.
Definition crypto.h:293
struct link_socket * sock
Definition event.h:145
event_arg_t type
Definition event.h:141
unsigned int rwflags
Definition event.h:123
interval_t n
periodic interval for periodic timeouts
Definition interval.h:137
int tun_mtu
the (user) configured tun-mtu.
Definition mtu.h:147
struct frame::@074234134026241341315172337061247271261307273127 buf
int payload_size
the maximum size that a payload that our buffers can hold from either tun device or network link.
Definition mtu.h:118
int headroom
the headroom in the buffer, this is choosen to allow all potential header to be added before the pack...
Definition mtu.h:124
uint16_t mss_fix
The actual MSS value that should be written to the payload packets.
Definition mtu.h:134
Garbage collection arena used to keep track of dynamically allocated memory.
Definition buffer.h:127
Security parameter state of one TLS and data channel key session.
Definition ssl_common.h:208
uint8_t dest[OPENVPN_ETH_ALEN]
Definition proto.h:55
uint16_t proto
Definition proto.h:62
uint8_t source[OPENVPN_ETH_ALEN]
Definition proto.h:56
uint8_t icmp6_type
Definition proto.h:143
uint16_t icmp6_cksum
Definition proto.h:147
uint8_t icmp6_code
Definition proto.h:146
uint32_t saddr
Definition proto.h:111
uint32_t daddr
Definition proto.h:112
uint8_t protocol
Definition proto.h:108
uint8_t version_len
Definition proto.h:93
uint8_t version_prio
Definition proto.h:121
struct in6_addr saddr
Definition proto.h:127
struct in6_addr daddr
Definition proto.h:128
uint8_t nexthdr
Definition proto.h:124
uint16_t payload_len
Definition proto.h:123
union openvpn_sockaddr::@051240265251124304325377241125360350250341115171 addr
struct sockaddr sa
Definition socket_util.h:42
struct sockaddr_in in4
Definition socket_util.h:43
struct sockaddr_in6 in6
Definition socket_util.h:44
const char * ifconfig_ipv6_remote
Definition options.h:331
int scheduled_exit_interval
Definition options.h:565
int shaper
Definition options.h:334
bool allow_recursive_routing
Definition options.h:720
int64_t inactivity_minimum_bytes
Definition options.h:346
int inactivity_timeout
Definition options.h:345
int handshake_window
Definition options.h:651
struct connection_entry ce
Definition options.h:294
int mode
Definition options.h:266
bool pull
Definition options.h:556
bool block_ipv6
Definition options.h:436
int ping_rec_timeout
Definition options.h:351
int ping_send_timeout
Definition options.h:350
bool route_gateway_via_dhcp
Definition options.h:438
struct client_nat_option_list * client_nat
Definition options.h:440
int session_timeout
Definition options.h:348
volatile int signal_received
Definition sig.h:42
struct event_timeout et
Definition status.h:62
int n_hard_errors
Definition ssl_common.h:637
enum multi_status multi_state
Definition ssl_common.h:632
struct tls_session session[TM_SIZE]
Array of tls_session objects representing control channel sessions with the remote peer.
Definition ssl_common.h:713
char * client_reason
An error message to send to client on AUTH_FAILED.
Definition ssl_common.h:666
bool use_peer_id
Definition ssl_common.h:701
int dco_peer_id
This is the handle that DCO uses to identify this session with the kernel.
Definition ssl_common.h:725
int n_soft_errors
Definition ssl_common.h:638
Security parameter state of a single session within a VPN tunnel.
Definition ssl_common.h:489
Definition tun.h:181
enum tun_driver_type backend_driver
The backend driver that used for this tun/tap device.
Definition tun.h:191
HANDLE hand
Definition tun.h:216
struct overlapped_io reads
Definition tun.h:219
dco_context_t dco
Definition tun.h:247
char * actual_name
Definition tun.h:205
#define SIGHUP
Definition syshead.h:55
unsigned short sa_family_t
Definition syshead.h:409
#define SIGTERM
Definition syshead.h:59
#define SIGUSR1
Definition syshead.h:57
uint32_t in_addr_t
Definition syshead.h:52
struct gc_arena gc
Definition test_ssl.c:122
void tun_show_debug(struct tuntap *tt)
Definition tun.c:6038
const char * tun_stat(const struct tuntap *tt, unsigned int rwflags, struct gc_arena *gc)
Definition tun.c:731
int tun_write_win32(struct tuntap *tt, struct buffer *buf)
Definition tun.c:3368
bool tun_standby(struct tuntap *tt)
Definition tun.c:5297
void show_adapters(msglvl_t msglevel)
Definition tun.c:4639
ssize_t write_tun(struct tuntap *tt, uint8_t *buf, int len)
static bool tuntap_abort(int status)
Definition tun.h:490
ssize_t read_tun(struct tuntap *tt, uint8_t *buf, int len)
#define TUNNEL_TYPE(tt)
Definition tun.h:182
static bool tuntap_defined(const struct tuntap *tt)
Definition tun.h:252
@ DRIVER_AFUNIX
using an AF_UNIX socket to pass packets from/to an external program.
Definition tun.h:51
static void tun_set(struct tuntap *tt, struct event_set *es, unsigned int rwflags, void *arg, unsigned int *persistent)
Definition tun.h:598
static bool tuntap_is_dco_win_timeout(struct tuntap *tt, ssize_t status)
Definition tun.h:538
static bool tuntap_stop(int status)
Definition tun.h:476
ssize_t read_tun_afunix(struct tuntap *tt, uint8_t *buf, int len)
Reads a packet from a AF_UNIX based tun device.
Definition tun_afunix.c:162
ssize_t write_tun_afunix(struct tuntap *tt, uint8_t *buf, int len)
Writes a packet to a AF_UNIX based tun device.
Definition tun_afunix.c:149