OpenVPN
forward.h
Go to the documentation of this file.
1/*
2 * OpenVPN -- An application to securely tunnel IP networks
3 * over a single TCP/UDP port, with support for SSL/TLS-based
4 * session authentication and key exchange,
5 * packet encryption, packet authentication, and
6 * packet compression.
7 *
8 * Copyright (C) 2002-2026 OpenVPN Inc <sales@openvpn.net>
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License version 2
12 * as published by the Free Software Foundation.
13 *
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 * GNU General Public License for more details.
18 *
19 * You should have received a copy of the GNU General Public License along
20 * with this program; if not, see <https://www.gnu.org/licenses/>.
21 */
22
23
28
29
30#ifndef FORWARD_H
31#define FORWARD_H
32
33/* the following macros must be defined before including any other header
34 * file
35 */
36
37#define TUN_OUT(c) (BLEN(&(c)->c2.to_tun) > 0)
38#define LINK_OUT(c) (BLEN(&(c)->c2.to_link) > 0)
39#define ANY_OUT(c) (TUN_OUT(c) || LINK_OUT(c))
40
41#ifdef ENABLE_FRAGMENT
42#define TO_LINK_FRAG(c) ((c)->c2.fragment && fragment_outgoing_defined((c)->c2.fragment))
43#else
44#define TO_LINK_FRAG(c) (false)
45#endif
46
47#define TO_LINK_DEF(c) (LINK_OUT(c) || TO_LINK_FRAG(c))
48
49#include "openvpn.h"
50#include "occ.h"
51#include "ping.h"
52#include "multi_io.h"
53
54#define IOW_TO_TUN (1 << 0)
55#define IOW_TO_LINK (1 << 1)
56#define IOW_READ_TUN (1 << 2)
57#define IOW_READ_LINK (1 << 3)
58#define IOW_SHAPER (1 << 4)
59#define IOW_CHECK_RESIDUAL (1 << 5)
60#define IOW_FRAG (1 << 6)
61#define IOW_READ_TUN_FORCE (1 << 8)
62#define IOW_WAIT_SIGNAL (1 << 9)
63
64#define IOW_READ (IOW_READ_TUN | IOW_READ_LINK)
65
67
69
85void multi_io_process_flags(struct context *c, struct event_set *es, struct link_socket *sock, const unsigned int flags);
86
87void io_wait(struct context *c, const unsigned int flags);
88
89void pre_select(struct context *c);
90
91void process_io(struct context *c, struct link_socket *sock);
92
93
94/**********************************************************************/
127void encrypt_sign(struct context *c, bool comp_frag);
128
129int get_server_poll_remaining_time(struct event_timeout *server_poll_timeout);
130
131/**********************************************************************/
152void read_incoming_link(struct context *c, struct link_socket *sock);
153
180bool process_incoming_link_part1(struct context *c, struct link_socket_info *lsi, bool floated);
181
207void process_incoming_link_part2(struct context *c, struct link_socket_info *lsi,
208 const uint8_t *orig_buf);
209
220void extract_dco_float_peer_addr(sa_family_t socket_family, struct openvpn_sockaddr *out_osaddr,
221 const struct sockaddr *float_sa);
222
229
243void process_outgoing_link(struct context *c, struct link_socket *sock);
244
245
246/**************************************************************************/
259void read_incoming_tun(struct context *c);
260
261
276void process_incoming_tun(struct context *c, struct link_socket *out_sock);
277
278
292void process_outgoing_tun(struct context *c, struct link_socket *in_sock);
293
294
295/**************************************************************************/
296
297/*
298 * Send a string to remote over the TLS control channel.
299 * Used for push/pull messages, passing username/password,
300 * etc.
301 * @param c - The context structure of the VPN tunnel associated with
302 * the packet.
303 * @param str - The message to be sent
304 * @param msglevel - Message level to use for logging
305 */
306bool send_control_channel_string(struct context *c, const char *str, msglvl_t msglevel);
307
308/*
309 * Send a string to remote over the TLS control channel.
310 * Used for push/pull messages, auth pending and other clear text
311 * control messages.
312 *
313 * This variant does not schedule the actual sending of the message
314 * The caller needs to ensure that it is scheduled or call
315 * send_control_channel_string
316 *
317 * @param session - The session structure of the VPN tunnel associated
318 * with the packet. The method will always use the
319 * primary key (KS_PRIMARY) for sending the message
320 * @param str - The message to be sent
321 * @param msglevel - Message level to use for logging
322 */
323
324bool send_control_channel_string_dowork(struct tls_session *session, const char *str,
325 msglvl_t msglevel);
326
327
334void reschedule_multi_process(struct context *c);
335
336#define PIPV4_PASSTOS (1u << 0)
337#define PIP_MSSFIX (1u << 1) /* v4 and v6 */
338#define PIP_OUTGOING (1u << 2)
339#define PIPV4_EXTRACT_DHCP_ROUTER (1u << 3)
340#define PIPV4_CLIENT_NAT (1u << 4)
341#define PIPV6_ICMP_NOHOST_CLIENT (1u << 5)
342#define PIPV6_ICMP_NOHOST_SERVER (1u << 6)
343
344
345void process_ip_header(struct context *c, unsigned int flags, struct buffer *buf,
346 struct link_socket *sock);
347
348bool schedule_exit(struct context *c);
349
350static inline struct link_socket_info *
352{
353 if (c->c2.link_socket_infos)
354 {
355 return c->c2.link_socket_infos[0];
356 }
357 else
358 {
359 return &c->c2.link_sockets[0]->info;
360 }
361}
362
363static inline void
364register_activity(struct context *c, const int64_t size)
365{
367 {
368 c->c2.inactivity_bytes += size;
370 {
371 c->c2.inactivity_bytes = 0;
373 }
374 }
375}
376
377/*
378 * Return the io_wait() flags appropriate for
379 * a point-to-point tunnel.
380 */
381static inline unsigned int
382p2p_iow_flags(const struct context *c)
383{
384 unsigned int flags = (IOW_SHAPER | IOW_CHECK_RESIDUAL | IOW_FRAG | IOW_READ | IOW_WAIT_SIGNAL);
385 if (c->c2.to_link.len > 0)
386 {
387 flags |= IOW_TO_LINK;
388 }
389 if (c->c2.to_tun.len > 0)
390 {
391 flags |= IOW_TO_TUN;
392 }
393 return flags;
394}
395
396
397static inline bool
399{
400 if (c->c2.tls_multi)
401 {
403 }
404 else
405 {
407 }
408}
409
410#endif /* FORWARD_H */
uint64_t counter_type
Definition common.h:31
void * dco_context_t
Definition dco.h:259
counter_type link_write_bytes_global
Definition forward.c:49
counter_type link_read_bytes_global
Definition forward.c:48
static unsigned int p2p_iow_flags(const struct context *c)
Definition forward.h:382
void process_incoming_dco(dco_context_t *dco)
Process an incoming DCO message (from kernel space).
Definition forward.c:1268
void reschedule_multi_process(struct context *c)
Reschedule tls_multi_process.
Definition forward.c:397
int get_server_poll_remaining_time(struct event_timeout *server_poll_timeout)
Definition forward.c:510
bool send_control_channel_string(struct context *c, const char *str, msglvl_t msglevel)
Definition forward.c:404
static void register_activity(struct context *c, const int64_t size)
Definition forward.h:364
#define IOW_WAIT_SIGNAL
Definition forward.h:62
void process_io(struct context *c, struct link_socket *sock)
Definition forward.c:2269
#define IOW_SHAPER
Definition forward.h:58
#define IOW_FRAG
Definition forward.h:60
bool schedule_exit(struct context *c)
Definition forward.c:534
void extract_dco_float_peer_addr(sa_family_t socket_family, struct openvpn_sockaddr *out_osaddr, const struct sockaddr *float_sa)
Transfers float_sa data extracted from an incoming DCO PEER_FLOAT_NTF to out_osaddr for later process...
Definition forward.c:1234
static struct link_socket_info * get_link_socket_info(struct context *c)
Definition forward.h:351
bool send_control_channel_string_dowork(struct tls_session *session, const char *str, msglvl_t msglevel)
Definition forward.c:376
void pre_select(struct context *c)
Definition forward.c:1988
#define IOW_CHECK_RESIDUAL
Definition forward.h:59
void io_wait(struct context *c, const unsigned int flags)
Definition forward.c:2148
static bool connection_established(struct context *c)
Definition forward.h:398
#define IOW_TO_TUN
Definition forward.h:54
void multi_io_process_flags(struct context *c, struct event_set *es, struct link_socket *sock, const unsigned int flags)
Processes I/O flags to configure socket and TUN/TAP event monitors.
Definition forward.c:2054
void process_ip_header(struct context *c, unsigned int flags, struct buffer *buf, struct link_socket *sock)
Definition forward.c:1685
#define IOW_READ
Definition forward.h:64
#define IOW_TO_LINK
Definition forward.h:55
void encrypt_sign(struct context *c, bool comp_frag)
Process a data channel packet that will be sent through a VPN tunnel.
Definition forward.c:644
bool process_incoming_link_part1(struct context *c, struct link_socket_info *lsi, bool floated)
Starts processing a packet read from the external network interface.
Definition forward.c:1008
void process_incoming_link_part2(struct context *c, struct link_socket_info *lsi, const uint8_t *orig_buf)
Continues processing a packet read from the external network interface.
Definition forward.c:1141
void process_outgoing_link(struct context *c, struct link_socket *sock)
Write a packet to the external network interface.
Definition forward.c:1769
void read_incoming_link(struct context *c, struct link_socket *sock)
Read a packet from the external network interface.
Definition forward.c:949
void read_incoming_tun(struct context *c)
Read a packet from the virtual tun/tap network interface.
Definition forward.c:1321
void process_incoming_tun(struct context *c, struct link_socket *out_sock)
Process a packet read from the virtual tun/tap network interface.
Definition forward.c:1500
void process_outgoing_tun(struct context *c, struct link_socket *in_sock)
Write a packet to the virtual tun/tap network interface.
Definition forward.c:1902
static void event_timeout_reset(struct event_timeout *et)
Resets a timer.
Definition interval.h:187
unsigned int msglvl_t
Definition error.h:77
@ CAS_WAITING_OPTIONS_IMPORT
client with pull or p2p waiting for first time options import
Definition ssl_common.h:586
Wrapper structure for dynamically allocated memory.
Definition buffer.h:71
int len
Length in bytes of the actual content within the allocated memory.
Definition buffer.h:76
struct tls_multi * tls_multi
TLS state structure for this VPN tunnel.
Definition openvpn.h:324
struct buffer to_link
Definition openvpn.h:377
int64_t inactivity_bytes
Definition openvpn.h:289
struct buffer to_tun
Definition openvpn.h:376
struct link_socket ** link_sockets
Definition openvpn.h:238
struct link_socket_info ** link_socket_infos
Definition openvpn.h:239
struct event_timeout inactivity_interval
Definition openvpn.h:288
Contains all state information for one tunnel.
Definition openvpn.h:471
struct context_2 c2
Level 2 context.
Definition openvpn.h:516
struct options options
Options loaded from command line or configuration file.
Definition openvpn.h:472
int64_t inactivity_minimum_bytes
Definition options.h:346
int inactivity_timeout
Definition options.h:345
enum multi_status multi_state
Definition ssl_common.h:632
Security parameter state of a single session within a VPN tunnel.
Definition ssl_common.h:489
unsigned short sa_family_t
Definition syshead.h:409