OpenVPN
multi.c
Go to the documentation of this file.
1/*
2 * OpenVPN -- An application to securely tunnel IP networks
3 * over a single TCP/UDP port, with support for SSL/TLS-based
4 * session authentication and key exchange,
5 * packet encryption, packet authentication, and
6 * packet compression.
7 *
8 * Copyright (C) 2002-2026 OpenVPN Inc <sales@openvpn.net>
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License version 2
12 * as published by the Free Software Foundation.
13 *
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 * GNU General Public License for more details.
18 *
19 * You should have received a copy of the GNU General Public License along
20 * with this program; if not, see <https://www.gnu.org/licenses/>.
21 */
22
23#ifdef HAVE_CONFIG_H
24#include "config.h"
25#endif
26
27#ifdef HAVE_SYS_INOTIFY_H
28#include <sys/inotify.h>
29#define INOTIFY_EVENT_BUFFER_SIZE 16384
30#endif
31
32#include "syshead.h"
33
34#include "forward.h"
35#include "multi.h"
36#include "push.h"
37#include "run_command.h"
38#include "otime.h"
39#include "gremlin.h"
40#include "ssl_verify.h"
41#include "ssl_ncp.h"
42#include "vlan.h"
43#include "auth_token.h"
44#include "route.h"
45#include "sid_hash.h"
46#include <inttypes.h>
47#include <string.h>
48
49#include "memdbg.h"
50
51
52#include "crypto_backend.h"
53#include "ssl_util.h"
54#include "dco.h"
55#include "reflect_filter.h"
56
57/*#define MULTI_DEBUG_EVENT_LOOP*/
58
59#ifdef MULTI_DEBUG_EVENT_LOOP
60static const char *
61id(struct multi_instance *mi)
62{
63 if (mi)
64 {
65 return tls_common_name(mi->context.c2.tls_multi, false);
66 }
67 else
68 {
69 return "NULL";
70 }
71}
72#endif
73
74#ifdef ENABLE_MANAGEMENT
75static void
76set_cc_config(struct multi_instance *mi, struct buffer_list *cc_config)
77{
79 mi->cc_config = cc_config;
80}
81#endif
82
83static bool
84learn_address_script(const struct multi_context *m, const struct multi_instance *mi, const char *op,
85 const struct mroute_addr *addr)
86{
87 struct gc_arena gc = gc_new();
88 struct env_set *es;
89 bool ret = true;
90 const struct plugin_list *plugins;
91
92 /* get environmental variable source */
93 if (mi && mi->context.c2.es)
94 {
95 es = mi->context.c2.es;
96 }
97 else
98 {
99 es = env_set_create(&gc);
100 }
101
102 /* get plugin source */
103 if (mi)
104 {
105 plugins = mi->context.plugins;
106 }
107 else
108 {
109 plugins = m->top.plugins;
110 }
111
112 if (plugin_defined(plugins, OPENVPN_PLUGIN_LEARN_ADDRESS))
113 {
114 struct argv argv = argv_new();
115 argv_printf(&argv, "%s %s", op, mroute_addr_print(addr, &gc));
116 if (mi)
117 {
119 }
120 if (plugin_call(plugins, OPENVPN_PLUGIN_LEARN_ADDRESS, &argv, NULL, es)
121 != OPENVPN_PLUGIN_FUNC_SUCCESS)
122 {
123 msg(M_WARN, "WARNING: learn-address plugin call failed");
124 ret = false;
125 }
126 argv_free(&argv);
127 }
128
130 {
131 struct argv argv = argv_new();
132 setenv_str(es, "script_type", "learn-address");
134 argv_printf_cat(&argv, "%s %s", op, mroute_addr_print(addr, &gc));
135 if (mi)
136 {
138 }
139 if (!openvpn_run_script(&argv, es, 0, "--learn-address"))
140 {
141 ret = false;
142 }
143 argv_free(&argv);
144 }
145
146 gc_free(&gc);
147 return ret;
148}
149
150void
152{
153 /* write pool data to file */
156 {
158 }
159}
160
161static void
162multi_reap_range(const struct multi_context *m, uint32_t start_bucket, uint32_t end_bucket)
163{
164 struct gc_arena gc = gc_new();
165 struct hash_iterator hi;
166 struct hash_element *he;
167
168 dmsg(D_MULTI_DEBUG, "MULTI: REAP range %u -> %u", start_bucket, end_bucket);
169 hash_iterator_init_range(m->vhash, &hi, start_bucket, end_bucket);
170 while ((he = hash_iterator_next(&hi)) != NULL)
171 {
172 struct multi_route *r = (struct multi_route *)he->value;
173 if (!multi_route_defined(m, r))
174 {
175 dmsg(D_MULTI_DEBUG, "MULTI: REAP DEL %s", mroute_addr_print(&r->addr, &gc));
176 learn_address_script(m, NULL, "delete", &r->addr);
179 }
180 }
182 gc_free(&gc);
183}
184
185static void
187{
189}
190
191static struct multi_reap *
193{
194 struct multi_reap *mr;
195 ALLOC_OBJ(mr, struct multi_reap);
196 mr->bucket_base = 0;
198 mr->last_call = now;
199 return mr;
200}
201
202void
204{
205 struct multi_reap *mr = m->reaper;
206 if (mr->bucket_base >= hash_n_buckets(m->vhash))
207 {
208 mr->bucket_base = 0;
209 }
211 mr->bucket_base += mr->buckets_per_pass;
212 mr->last_call = now;
213}
214
215static void
217{
218 free(mr);
219}
220
221/*
222 * How many buckets in vhash to reap per pass.
223 */
224static uint32_t
225reap_buckets_per_pass(uint32_t n_buckets)
226{
227 return constrain_uint(n_buckets / REAP_DIVISOR, REAP_MIN, REAP_MAX);
228}
229
230#ifdef ENABLE_MANAGEMENT
231
232static uint64_t
233cid_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
234{
235 const unsigned long *k = (const unsigned long *)key;
236 return (uint64_t)*k;
237}
238
239static bool
240cid_compare_function(const void *key1, const void *key2)
241{
242 const unsigned long *k1 = (const unsigned long *)key1;
243 const unsigned long *k2 = (const unsigned long *)key2;
244 return *k1 == *k2;
245}
246
247#endif
248
249#ifdef ENABLE_ASYNC_PUSH
250static uint64_t
251/*
252 * inotify watcher descriptors are used as hash value
253 */
254int_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
255{
256 return (uintptr_t)key;
257}
258
259static bool
260int_compare_function(const void *key1, const void *key2)
261{
262 return (uintptr_t)key1 == (uintptr_t)key2;
263}
264#endif
265
266/*
267 * Main initialization function, init multi_context object.
268 */
269static void
271{
272 struct multi_context *m = t->multi;
273 int dev = DEV_TYPE_UNDEF;
274
275 msg(D_MULTI_LOW, "MULTI: multi_init called, r=%" PRIu32 " v=%" PRIu32 " s=%" PRIu32,
277
278 /*
279 * Get tun/tap/null device type
280 */
282
283 /*
284 * Init our multi_context object.
285 */
286 CLEAR(*m);
287
288 /*
289 * Real address hash table (source port number is
290 * considered to be part of the address). Used
291 * to determine which client sent an incoming packet
292 * which is seen on the TCP/UDP socket.
293 */
296
297 /*
298 * Virtual address hash table. Used to determine
299 * which client to route a packet to.
300 */
303
304 /*
305 * Peer session id hash table. Used to lookup a session by the session
306 * id of one of its active sessions */
309
310#ifdef ENABLE_MANAGEMENT
312#endif
313
314#ifdef ENABLE_ASYNC_PUSH
315 /*
316 * Mapping between inotify watch descriptors and
317 * multi_instances.
318 */
319 m->inotify_watchers =
320 hash_init(t->options.real_hash_size, int_hash_function, int_compare_function);
321#endif
322
323 /*
324 * This is our scheduler, for time-based wakeup
325 * events.
326 */
327 m->schedule = schedule_init();
328
329 /*
330 * Limit frequency of incoming connections to control
331 * DoS.
332 */
336
337 /*
338 * Allocate broadcast/multicast buffer list
339 */
341
342 /*
343 * Different status file format options are available
344 */
346
347 /*
348 * Possibly allocate an ifconfig pool, do it
349 * differently based on whether a tun or tap style
350 * tunnel.
351 */
353 {
355
356 if (dev == DEV_TYPE_TUN && t->options.topology == TOP_NET30)
357 {
359 }
360
366
367 /* reload pool data from file */
369 {
371 }
372 }
373
374 /*
375 * Help us keep track of routing table.
376 */
378
379 /*
380 * Initialize route and instance reaper.
381 */
383
384 /*
385 * Get local ifconfig address
386 */
387 CLEAR(m->local);
388 ASSERT(t->c1.tuntap);
390
391 /*
392 * Per-client limits
393 */
395
396 m->instances = calloc(m->max_clients, sizeof(struct multi_instance *));
397
398 m->top.c2.event_set = t->c2.event_set;
399
400 /*
401 * Initialize multi-socket I/O wait object
402 */
405
406 /*
407 * Allow client <-> client communication, without going through
408 * tun/tap interface and network stack?
409 */
411
412 /* initialize stale routes check timer */
414 {
415 msg(M_INFO,
416 "Initializing stale route check timer to run every %i seconds and to removing routes with activity timeout older than %i seconds",
419 }
420
422}
423
424const char *
425multi_instance_string(const struct multi_instance *mi, bool null, struct gc_arena *gc)
426{
427 if (mi)
428 {
430 const char *cn = tls_common_name(mi->context.c2.tls_multi, true);
431
432 if (cn)
433 {
434 buf_printf(&out, "%s/", cn);
435 }
436 buf_printf(&out, "%s", mroute_addr_print(&mi->real, gc));
437
438 bool debug_rx_pid = (check_debug_level(D_DCO_DEBUG) && dco_enabled(&mi->context.options))
440
441 if (mi->context.c2.tls_multi && debug_rx_pid)
442 {
443 buf_printf(&out, " rx-peer-id=%u", mi->context.c2.tls_multi->rx_peer_id);
444 }
445 return BSTR(&out);
446 }
447 else if (null)
448 {
449 return NULL;
450 }
451 else
452 {
453 return "UNDEF";
454 }
455}
456
457static void
459{
460 struct gc_arena gc = gc_new();
461 const char *prefix = multi_instance_string(mi, true, &gc);
462 if (prefix)
463 {
464 strncpynt(mi->msg_prefix, prefix, sizeof(mi->msg_prefix));
465 }
466 else
467 {
468 mi->msg_prefix[0] = '\0';
469 }
470 set_prefix(mi);
471 gc_free(&gc);
472}
473
474void
476{
477 mi->msg_prefix[0] = '\0';
478 set_prefix(mi);
479}
480
481/*
482 * Tell the route helper about deleted iroutes so
483 * that it can update its mask of currently used
484 * CIDR netlengths.
485 */
486static void
488{
489 const struct iroute *ir;
490 const struct iroute_ipv6 *ir6;
491
492 /* check if DCO iroutes were already removed when scheduling a delayed exit */
493 if (mi->context.did_dco_iroutes)
494 {
495 mi->context.did_dco_iroutes = false;
497 }
498
500 {
501 for (ir = mi->context.options.iroutes; ir != NULL; ir = ir->next)
502 {
504 }
505
506 for (ir6 = mi->context.options.iroutes_ipv6; ir6 != NULL; ir6 = ir6->next)
507 {
509 }
510 }
511}
512
513static void
515{
516 setenv_counter(c->c2.es, "bytes_received", c->c2.link_read_bytes + c->c2.dco_read_bytes);
517 setenv_counter(c->c2.es, "bytes_sent", c->c2.link_write_bytes + c->c2.dco_write_bytes);
518}
519
520static void
522{
523 /* setenv client real IP address */
525
526 /* setenv stats */
527 setenv_stats(&mi->context);
528
529 /* setenv connection duration */
530 setenv_long_long(mi->context.c2.es, "time_duration", now - mi->created);
531}
532
533static void
535{
537
538 if (plugin_defined(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_DISCONNECT))
539 {
540 if (plugin_call(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_DISCONNECT, NULL, NULL,
541 mi->context.c2.es)
542 != OPENVPN_PLUGIN_FUNC_SUCCESS)
543 {
544 msg(M_WARN, "WARNING: client-disconnect plugin call failed");
545 }
546 }
547
549 {
550 struct argv argv = argv_new();
551 setenv_str(mi->context.c2.es, "script_type", "client-disconnect");
553 openvpn_run_script(&argv, mi->context.c2.es, 0, "--client-disconnect");
554 argv_free(&argv);
555 }
556#ifdef ENABLE_MANAGEMENT
557 if (management)
558 {
560 }
561#endif
562}
563
564void
565multi_close_instance(struct multi_context *m, struct multi_instance *mi, bool shutdown)
566{
567 ASSERT(!mi->halt);
568 mi->halt = true;
569 bool is_dgram = proto_is_dgram(mi->context.c2.link_sockets[0]->info.proto);
570
571 dmsg(D_MULTI_DEBUG, "MULTI: multi_close_instance called");
572
573 /* adjust current client connection count */
574 m->n_clients += mi->n_clients_delta;
575 mi->n_clients_delta = 0;
576
577 /* prevent dangling pointers */
578 if (m->pending == mi)
579 {
580 multi_set_pending(m, NULL);
581 }
582 if (m->earliest_wakeup == mi)
583 {
584 m->earliest_wakeup = NULL;
585 }
586
587 if (!shutdown)
588 {
589 if (mi->did_real_hash)
590 {
591 ASSERT(hash_remove(m->hash, &mi->real));
592 }
593#ifdef ENABLE_MANAGEMENT
594 if (mi->did_cid_hash)
595 {
597 }
598#endif
599
600#ifdef ENABLE_ASYNC_PUSH
601 if (mi->inotify_watch != -1)
602 {
603 hash_remove(m->inotify_watchers, (void *)(uintptr_t)mi->inotify_watch);
604 mi->inotify_watch = -1;
605 }
606#endif
607
608
610 {
612 }
613
615 {
616 m->instances[mi->context.c2.tls_multi->rx_peer_id] = NULL;
617
618 /* Adjust the max_peerid as this might have been the highest
619 * peer id instance */
620 while (m->max_peerid > 0 && m->instances[m->max_peerid] == NULL)
621 {
622 m->max_peerid--;
623 }
624 }
625
627
628 ifconfig_pool_release(m->ifconfig_pool, mi->vaddr_handle, false);
629
630 if (mi->did_iroutes)
631 {
632 multi_del_iroutes(m, mi);
633 mi->did_iroutes = false;
634 }
635
636 if (!is_dgram)
637 {
639 }
640
642 }
643
644#ifdef ENABLE_MANAGEMENT
645 set_cc_config(mi, NULL);
646#endif
647
649 {
651 }
652
654
656
658
659 /*
660 * Don't actually delete the instance memory allocation yet,
661 * because virtual routes may still point to it. Let the
662 * vhash reaper deal with it.
663 */
665}
666
667/*
668 * Called on shutdown or restart.
669 */
670static void
672{
673 if (m->hash)
674 {
675 /* fetch final stats while all peers can still be mapped to their instances */
676 if (dco_enabled(&m->top.options))
677 {
679 }
680
681 for (uint32_t i = 0; i <= m->max_peerid; i++)
682 {
683 struct multi_instance *mi = m->instances[i];
684 if (mi)
685 {
686 multi_close_instance(m, mi, true);
687 }
688 }
689
691
692 hash_free(m->hash);
693 hash_free(m->vhash);
695#ifdef ENABLE_MANAGEMENT
697#endif
698 m->hash = NULL;
699
700 free(m->instances);
701
702#ifdef ENABLE_ASYNC_PUSH
703 hash_free(m->inotify_watchers);
704 m->inotify_watchers = NULL;
705#endif
706
708 mbuf_free(m->mbuf);
715 }
716}
717
718/*
719 * Create a client instance object for a newly connected client.
720 */
721struct multi_instance *
723 struct link_socket *sock)
724{
725 struct gc_arena gc = gc_new();
726 struct multi_instance *mi;
727
728 msg(D_MULTI_MEDIUM, "MULTI: multi_create_instance called");
729
731
732 mi->gc = gc_new();
734 mi->vaddr_handle = -1;
735 mi->created = now;
737
738 if (real)
739 {
740 mi->real = *real;
741 generate_prefix(mi);
742 }
743
744 inherit_context_child(&mi->context, &m->top, sock);
745 if (IS_SIG(&mi->context))
746 {
747 goto err;
748 }
749
751
752 if (hash_n_elements(m->hash) >= m->max_clients)
753 {
755 "MULTI: new incoming connection would exceed maximum number of clients (%u)",
756 m->max_clients);
757 goto err;
758 }
759
760 if (!real) /* TCP mode? */
761 {
763 {
764 goto err;
765 }
766 generate_prefix(mi);
767 }
768
769#ifdef ENABLE_MANAGEMENT
770 do
771 {
773 } while (!hash_add(m->cid_hash, &mi->context.c2.mda_context.cid, mi, false));
774 mi->did_cid_hash = true;
775#endif
776
777 mi->context.c2.push_request_received = false;
778#ifdef ENABLE_ASYNC_PUSH
779 mi->inotify_watch = -1;
780#endif
781
783 {
784 msg(D_MULTI_ERRORS, "MULTI: signal occurred during client instance initialization");
785 goto err;
786 }
787
789 mi->ev_arg.u.mi = mi;
790
791 gc_free(&gc);
792 return mi;
793
794err:
795 multi_close_instance(m, mi, false);
796 gc_free(&gc);
797 return NULL;
798}
799
800/*
801 * Dump tables -- triggered by SIGUSR2.
802 * If status file is defined, write to file.
803 * If status file is NULL, write to syslog.
804 */
805static void
806multi_print_status(struct multi_context *m, struct status_output *so, const int version)
807{
808 if (m->hash)
809 {
810 struct gc_arena gc_top = gc_new();
811 struct hash_iterator hi;
812 const struct hash_element *he;
813
814 status_reset(so);
815
816 if (dco_enabled(&m->top.options))
817 {
818 if (dco_get_peer_stats_multi(&m->top.c1.tuntap->dco, true) < 0)
819 {
820 return;
821 }
822 }
823
824 if (version == 1)
825 {
826 /*
827 * Status file version 1
828 */
829 status_printf(so, "OpenVPN CLIENT LIST");
830 status_printf(so, "Updated,%s", time_string(0, 0, false, &gc_top));
831 status_printf(so, "Common Name,Real Address,Bytes Received,Bytes Sent,Connected Since");
832 hash_iterator_init(m->hash, &hi);
833 while ((he = hash_iterator_next(&hi)))
834 {
835 struct gc_arena gc = gc_new();
836 const struct multi_instance *mi = (struct multi_instance *)he->value;
837
838 if (!mi->halt)
839 {
840 status_printf(so, "%s,%s," counter_format "," counter_format ",%s",
842 mroute_addr_print(&mi->real, &gc),
845 time_string(mi->created, 0, false, &gc));
846 }
847 gc_free(&gc);
848 }
850
851 status_printf(so, "ROUTING TABLE");
852 status_printf(so, "Virtual Address,Common Name,Real Address,Last Ref");
853 hash_iterator_init(m->vhash, &hi);
854 while ((he = hash_iterator_next(&hi)))
855 {
856 struct gc_arena gc = gc_new();
857 const struct multi_route *route = (struct multi_route *)he->value;
858
860 {
861 const struct multi_instance *mi = route->instance;
862 const struct mroute_addr *ma = &route->addr;
863 char flags[2] = { 0, 0 };
864
865 if (route->flags & MULTI_ROUTE_CACHE)
866 {
867 flags[0] = 'C';
868 }
869 status_printf(so, "%s%s,%s,%s,%s", mroute_addr_print(ma, &gc), flags,
871 mroute_addr_print(&mi->real, &gc),
872 time_string(route->last_reference, 0, false, &gc));
873 }
874 gc_free(&gc);
875 }
877
878 status_printf(so, "GLOBAL STATS");
879 if (m->mbuf)
880 {
881 status_printf(so, "Max bcast/mcast queue length,%d", mbuf_maximum_queued(m->mbuf));
882 }
883
884 status_printf(so, "END");
885 }
886 else if (version == 2 || version == 3)
887 {
888 const char sep = (version == 3) ? '\t' : ',';
889
890 /*
891 * Status file version 2 and 3
892 */
893 status_printf(so, "TITLE%c%s", sep, title_string);
894 status_printf(so, "TIME%c%s%c%u", sep, time_string(now, 0, false, &gc_top), sep,
895 (unsigned int)now);
897 so,
898 "HEADER%cCLIENT_LIST%cCommon Name%cReal Address%cVirtual Address%cVirtual IPv6 Address%cBytes Received%cBytes Sent%cConnected Since%cConnected Since (time_t)%cUsername%cClient ID%cPeer ID%cData Channel Cipher",
899 sep, sep, sep, sep, sep, sep, sep, sep, sep, sep, sep, sep, sep);
900 hash_iterator_init(m->hash, &hi);
901 while ((he = hash_iterator_next(&hi)))
902 {
903 struct gc_arena gc = gc_new();
904 const struct multi_instance *mi = (struct multi_instance *)he->value;
905
906 if (!mi->halt)
907 {
909 so,
910 "CLIENT_LIST%c%s%c%s%c%s%c%s%c" counter_format "%c" counter_format
911 "%c%s%c%u%c%s%c"
912#ifdef ENABLE_MANAGEMENT
913 "%lu"
914#else
915 ""
916#endif
917 "%c%" PRIu32 "%c%s",
918 sep, tls_common_name(mi->context.c2.tls_multi, false), sep,
919 mroute_addr_print(&mi->real, &gc), sep,
924 time_string(mi->created, 0, false, &gc), sep, (unsigned int)mi->created,
925 sep, tls_username(mi->context.c2.tls_multi, false),
926#ifdef ENABLE_MANAGEMENT
927 sep, mi->context.c2.mda_context.cid,
928#else
929 sep,
930#endif
933 }
934 gc_free(&gc);
935 }
937
939 so,
940 "HEADER%cROUTING_TABLE%cVirtual Address%cCommon Name%cReal Address%cLast Ref%cLast Ref (time_t)",
941 sep, sep, sep, sep, sep, sep);
942 hash_iterator_init(m->vhash, &hi);
943 while ((he = hash_iterator_next(&hi)))
944 {
945 struct gc_arena gc = gc_new();
946 const struct multi_route *route = (struct multi_route *)he->value;
947
949 {
950 const struct multi_instance *mi = route->instance;
951 const struct mroute_addr *ma = &route->addr;
952 char flags[2] = { 0, 0 };
953
954 if (route->flags & MULTI_ROUTE_CACHE)
955 {
956 flags[0] = 'C';
957 }
958 status_printf(so, "ROUTING_TABLE%c%s%s%c%s%c%s%c%s%c%u", sep,
959 mroute_addr_print(ma, &gc), flags, sep,
960 tls_common_name(mi->context.c2.tls_multi, false), sep,
961 mroute_addr_print(&mi->real, &gc), sep,
962 time_string(route->last_reference, 0, false, &gc), sep,
963 (unsigned int)route->last_reference);
964 }
965 gc_free(&gc);
966 }
968
969 if (m->mbuf)
970 {
971 status_printf(so, "GLOBAL_STATS%cMax bcast/mcast queue length%c%d", sep, sep,
973 }
974
975 status_printf(so, "GLOBAL_STATS%cdco_enabled%c%d", sep, sep,
976 dco_enabled(&m->top.options));
977 status_printf(so, "END");
978 }
979 else
980 {
981 status_printf(so, "ERROR: bad status format version number");
982 }
983
984#ifdef PACKET_TRUNCATION_CHECK
985 {
986 status_printf(so, "HEADER,ERRORS,Common Name,TUN Read Trunc,TUN Write Trunc,Pre-encrypt Trunc,Post-decrypt Trunc");
987 hash_iterator_init(m->hash, &hi);
988 while ((he = hash_iterator_next(&hi)))
989 {
990 struct gc_arena gc = gc_new();
991 const struct multi_instance *mi = (struct multi_instance *)he->value;
992
993 if (!mi->halt)
994 {
995 status_printf(so,
996 "ERRORS,%s," counter_format "," counter_format "," counter_format
997 "," counter_format,
999 m->top.c2.n_trunc_tun_read, mi->context.c2.n_trunc_tun_write,
1000 mi->context.c2.n_trunc_pre_encrypt,
1001 mi->context.c2.n_trunc_post_decrypt);
1002 }
1003 gc_free(&gc);
1004 }
1005 hash_iterator_free(&hi);
1006 }
1007#endif /* ifdef PACKET_TRUNCATION_CHECK */
1008
1009 status_flush(so);
1010 gc_free(&gc_top);
1011 }
1012
1013#ifdef ENABLE_ASYNC_PUSH
1014 if (m->inotify_watchers)
1015 {
1016 msg(D_MULTI_DEBUG, "inotify watchers count: %u", hash_n_elements(m->inotify_watchers));
1017 }
1018#endif
1019}
1020
1021/*
1022 * Learn a virtual address or route.
1023 * The learn will fail if the learn address
1024 * script/plugin fails. In this case the
1025 * return value may be != mi.
1026 * Return the instance which owns this route,
1027 * or NULL if none.
1028 */
1029static struct multi_instance *
1030multi_learn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr,
1031 const unsigned int flags)
1032{
1033 struct hash_element *he;
1034 const uint64_t hv = hash_value(m->vhash, addr);
1035 struct hash_bucket *bucket = hash_bucket(m->vhash, hv);
1036 struct multi_route *oldroute = NULL;
1037 struct multi_instance *owner = NULL;
1038 struct gc_arena gc = gc_new();
1039
1040 /* if route currently exists, get the instance which owns it */
1041 he = hash_lookup_fast(m->vhash, bucket, addr, hv);
1042 if (he)
1043 {
1044 oldroute = (struct multi_route *)he->value;
1045 }
1046 if (oldroute && multi_route_defined(m, oldroute))
1047 {
1048 owner = oldroute->instance;
1049 }
1050
1051 /* do we need to add address to hash table? */
1052 if ((!owner || owner != mi) && mroute_learnable_address(addr, &gc)
1053 && !mroute_addr_equal(addr, &m->local))
1054 {
1055 struct multi_route *newroute;
1056 bool learn_succeeded = false;
1057
1058 ALLOC_OBJ(newroute, struct multi_route);
1059 newroute->addr = *addr;
1060 newroute->instance = mi;
1061 newroute->flags = flags;
1062 newroute->last_reference = now;
1063 newroute->cache_generation = 0;
1064
1065 /* The cache is invalidated when cache_generation is incremented */
1067 {
1069 }
1070
1071 if (oldroute) /* route already exists? */
1072 {
1073 if (route_quota_test(mi) && learn_address_script(m, mi, "update", &newroute->addr))
1074 {
1075 learn_succeeded = true;
1076 owner = mi;
1078 route_quota_inc(mi);
1079
1080 /* delete old route */
1081 multi_route_del(oldroute);
1082
1083 /* modify hash table entry, replacing old route */
1084 he->key = &newroute->addr;
1085 he->value = newroute;
1086 }
1087 }
1088 else
1089 {
1090 if (route_quota_test(mi) && learn_address_script(m, mi, "add", &newroute->addr))
1091 {
1092 learn_succeeded = true;
1093 owner = mi;
1095 route_quota_inc(mi);
1096
1097 /* add new route */
1098 hash_add_fast(m->vhash, bucket, &newroute->addr, hv, newroute);
1099 }
1100 }
1101
1102 msg(D_MULTI_LOW, "MULTI: Learn%s: %s -> %s", learn_succeeded ? "" : " FAILED",
1103 mroute_addr_print(&newroute->addr, &gc), multi_instance_string(mi, false, &gc));
1104
1105 if (!learn_succeeded)
1106 {
1107 free(newroute);
1108 }
1109 }
1110 gc_free(&gc);
1111
1112 return owner;
1113}
1114
1115/*
1116 * Get client instance based on virtual address.
1117 */
1118static struct multi_instance *
1120 bool cidr_routing)
1121{
1122 struct multi_route *route;
1123 struct multi_instance *ret = NULL;
1124
1125 /* check for local address */
1126 if (mroute_addr_equal(addr, &m->local))
1127 {
1128 return NULL;
1129 }
1130
1131 route = (struct multi_route *)hash_lookup(m->vhash, addr);
1132
1133 /* does host route (possible cached) exist? */
1134 if (route && multi_route_defined(m, route))
1135 {
1136 struct multi_instance *mi = route->instance;
1137 route->last_reference = now;
1138 ret = mi;
1139 }
1140 else if (cidr_routing) /* do we need to regenerate a host route cache entry? */
1141 {
1142 struct mroute_helper *rh = m->route_helper;
1143 struct mroute_addr tryaddr;
1144 int i;
1145
1146 /* cycle through each CIDR length */
1147 for (i = 0; i < rh->n_net_len; ++i)
1148 {
1149 tryaddr = *addr;
1150 tryaddr.type |= MR_WITH_NETBITS;
1151 tryaddr.netbits = rh->net_len[i];
1153
1154 /* look up a possible route with netbits netmask */
1155 route = (struct multi_route *)hash_lookup(m->vhash, &tryaddr);
1156
1157 if (route && multi_route_defined(m, route))
1158 {
1159 /* found an applicable route, cache host route */
1160 struct multi_instance *mi = route->instance;
1162 ret = mi;
1163 break;
1164 }
1165 }
1166 }
1167
1168#ifndef ENABLE_SMALL
1170 {
1171 struct gc_arena gc = gc_new();
1172 const char *addr_text = mroute_addr_print(addr, &gc);
1173 if (ret)
1174 {
1175 dmsg(D_MULTI_DEBUG, "GET INST BY VIRT: %s -> %s via %s", addr_text,
1176 multi_instance_string(ret, false, &gc), mroute_addr_print(&route->addr, &gc));
1177 }
1178 else
1179 {
1180 dmsg(D_MULTI_DEBUG, "GET INST BY VIRT: %s [failed]", addr_text);
1181 }
1182 gc_free(&gc);
1183 }
1184#endif
1185
1186 ASSERT(!(ret && ret->halt));
1187 return ret;
1188}
1189
1190/*
1191 * Helper function to multi_learn_addr().
1192 */
1193static struct multi_instance *
1195 int netbits, /* -1 if host route, otherwise # of network bits in address */
1196 bool primary)
1197{
1198 struct openvpn_sockaddr remote_si;
1199 struct mroute_addr addr = { 0 };
1200
1201 CLEAR(remote_si);
1202 remote_si.addr.in4.sin_family = AF_INET;
1203 remote_si.addr.in4.sin_addr.s_addr = htonl(a);
1204 addr.proto = 0;
1205 ASSERT(mroute_extract_openvpn_sockaddr(&addr, &remote_si, false));
1206
1207 if (netbits >= 0)
1208 {
1209 addr.type |= MR_WITH_NETBITS;
1210 addr.netbits = (uint8_t)netbits;
1211 }
1212
1213 struct multi_instance *owner = multi_learn_addr(m, mi, &addr, MULTI_ROUTE_PERMANENT);
1214#ifdef ENABLE_MANAGEMENT
1215 if (management && owner)
1216 {
1217 management_learn_addr(&mi->context.c2.mda_context, &addr, primary);
1218 }
1219#endif
1220 if (primary && multi_check_push_ifconfig_extra_route(&mi->context.options, addr.v4.addr))
1221 {
1222 /* "primary" is the VPN ifconfig address of the peer */
1223 /* if it does not fall into the network defined by ifconfig_local
1224 * we install this as extra onscope address on the interface */
1225 addr.netbits = 32;
1226 addr.type |= MR_ONLINK_DCO_ADDR;
1227
1228 dco_install_iroute(m, mi, &addr);
1229 }
1230 else if (!primary)
1231 {
1232 ASSERT(netbits >= 0); /* DCO requires populated netbits */
1233 dco_install_iroute(m, mi, &addr);
1234 }
1235
1236 return owner;
1237}
1238
1239static struct multi_instance *
1240multi_learn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6,
1241 int netbits, /* -1 if host route, otherwise # of network bits in address */
1242 bool primary)
1243{
1244 struct mroute_addr addr = { 0 };
1245
1246 addr.len = 16;
1247 addr.type = MR_ADDR_IPV6;
1248 addr.netbits = 0;
1249 addr.v6.addr = a6;
1250
1251 if (netbits >= 0)
1252 {
1253 addr.type |= MR_WITH_NETBITS;
1254 addr.netbits = (uint8_t)netbits;
1256 }
1257
1258 struct multi_instance *owner = multi_learn_addr(m, mi, &addr, MULTI_ROUTE_PERMANENT);
1259#ifdef ENABLE_MANAGEMENT
1260 if (management && owner)
1261 {
1262 management_learn_addr(&mi->context.c2.mda_context, &addr, primary);
1263 }
1264#endif
1266 {
1267 /* "primary" is the VPN ifconfig address of the peer */
1268 /* if it does not fall into the network defined by ifconfig_local
1269 * we install this as extra onscope address on the interface */
1270 addr.netbits = 128;
1271 addr.type |= MR_ONLINK_DCO_ADDR;
1272
1273 dco_install_iroute(m, mi, &addr);
1274 }
1275 else if (!primary)
1276 {
1277 /* "primary" is the VPN ifconfig address of the peer and already
1278 * known to DCO, so only install "extra" iroutes (primary = false)
1279 */
1280 ASSERT(netbits >= 0); /* DCO requires populated netbits */
1281 dco_install_iroute(m, mi, &addr);
1282 }
1283
1284 return owner;
1285}
1286
1287/*
1288 * A new client has connected, add routes (server -> client)
1289 * to internal routing table.
1290 */
1291static void
1293{
1294 struct gc_arena gc = gc_new();
1295 const struct iroute *ir;
1296 const struct iroute_ipv6 *ir6;
1298 {
1299 mi->did_iroutes = true;
1300 /* multi_learn_in{6}_addr_t takes care of installing the DCO iroute */
1301 mi->context.did_dco_iroutes = true;
1302 for (ir = mi->context.options.iroutes; ir != NULL; ir = ir->next)
1303 {
1304 if (ir->netbits >= 0)
1305 {
1306 msg(D_MULTI_LOW, "MULTI: internal route %s/%d -> %s",
1307 print_in_addr_t(ir->network, 0, &gc), ir->netbits,
1308 multi_instance_string(mi, false, &gc));
1309 }
1310 else
1311 {
1312 msg(D_MULTI_LOW, "MULTI: internal route %s -> %s",
1313 print_in_addr_t(ir->network, 0, &gc), multi_instance_string(mi, false, &gc));
1314 }
1315
1317
1318 multi_learn_in_addr_t(m, mi, ir->network, ir->netbits, false);
1319 }
1320 for (ir6 = mi->context.options.iroutes_ipv6; ir6 != NULL; ir6 = ir6->next)
1321 {
1322 msg(D_MULTI_LOW, "MULTI: internal route %s/%u -> %s",
1323 print_in6_addr(ir6->network, 0, &gc), ir6->netbits,
1324 multi_instance_string(mi, false, &gc));
1325
1327
1328 multi_learn_in6_addr(m, mi, ir6->network, ir6->netbits, false);
1329 }
1330 }
1331 gc_free(&gc);
1332}
1333
1334/*
1335 * Given an instance (new_mi), delete all other instances which use the
1336 * same common name.
1337 */
1338static void
1340{
1341 if (new_mi)
1342 {
1343 const char *new_cn = tls_common_name(new_mi->context.c2.tls_multi, true);
1344 if (new_cn)
1345 {
1346 int count = 0;
1347
1348 for (uint32_t i = 0; i <= m->max_peerid; i++)
1349 {
1350 struct multi_instance *mi = m->instances[i];
1351 if (mi && mi != new_mi && !mi->halt)
1352 {
1353 const char *cn = tls_common_name(mi->context.c2.tls_multi, true);
1354 if (cn && !strcmp(cn, new_cn))
1355 {
1356 multi_close_instance(m, mi, false);
1357 ++count;
1358 }
1359 }
1360 }
1361
1362 if (count)
1363 {
1365 "MULTI: new connection by client '%s' will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.",
1366 new_cn);
1367 }
1368 }
1369 }
1370}
1371
1372static void
1374{
1375 struct gc_arena gc = gc_new();
1376 struct hash_iterator hi;
1377 struct hash_element *he;
1378
1379 dmsg(D_MULTI_DEBUG, "MULTI: Checking stale routes");
1381 while ((he = hash_iterator_next(&hi)) != NULL)
1382 {
1383 struct multi_route *r = (struct multi_route *)he->value;
1385 && difftime(now, r->last_reference) >= m->top.options.stale_routes_ageing_time)
1386 {
1387 dmsg(D_MULTI_DEBUG, "MULTI: Deleting stale route for address '%s'",
1388 mroute_addr_print(&r->addr, &gc));
1389 learn_address_script(m, NULL, "delete", &r->addr);
1390 multi_route_del(r);
1392 }
1393 }
1394 hash_iterator_free(&hi);
1395 gc_free(&gc);
1396}
1397
1398/*
1399 * Ensure that endpoint to be pushed to client
1400 * complies with --ifconfig-push-constraint directive.
1401 */
1402static bool
1404{
1405 const struct options *o = &c->options;
1407 {
1410 }
1411 else
1412 {
1413 return true;
1414 }
1415}
1416
1417/*
1418 * Select a virtual address for a new client instance.
1419 * Use an --ifconfig-push directive, if given (static IP).
1420 * Otherwise use an --ifconfig-pool address (dynamic IP).
1421 */
1422static void
1424{
1425 struct gc_arena gc = gc_new();
1426
1427 /*
1428 * If ifconfig addresses were set by dynamic config file,
1429 * release pool addresses, otherwise keep them.
1430 */
1432 {
1433 /* ifconfig addresses were set statically,
1434 * release dynamic allocation */
1435 if (mi->vaddr_handle >= 0)
1436 {
1438 mi->vaddr_handle = -1;
1439 }
1440
1441 mi->context.c2.push_ifconfig_defined = true;
1446
1447 /* the current implementation does not allow "static IPv4, pool IPv6",
1448 * (see below) so issue a warning if that happens - don't break the
1449 * session, though, as we don't even know if this client WANTS IPv6
1450 */
1453 {
1454 msg(M_INFO,
1455 "MULTI_sva: WARNING: if --ifconfig-push is used for IPv4, automatic IPv6 assignment from --ifconfig-ipv6-pool does not work. Use --ifconfig-ipv6-push for IPv6 then.");
1456 }
1457 }
1458 else if (m->ifconfig_pool && mi->vaddr_handle < 0) /* otherwise, choose a pool address */
1459 {
1460 in_addr_t local = 0, remote = 0;
1461 struct in6_addr remote_ipv6;
1462 const char *cn = NULL;
1463
1464 if (!mi->context.options.duplicate_cn)
1465 {
1466 cn = tls_common_name(mi->context.c2.tls_multi, true);
1467 }
1468
1469 CLEAR(remote_ipv6);
1470 mi->vaddr_handle =
1471 ifconfig_pool_acquire(m->ifconfig_pool, &local, &remote, &remote_ipv6, cn);
1472 if (mi->vaddr_handle >= 0)
1473 {
1474 const int tunnel_type = TUNNEL_TYPE(mi->context.c1.tuntap);
1475 const int tunnel_topology = TUNNEL_TOPOLOGY(mi->context.c1.tuntap);
1476
1477 msg(M_INFO, "MULTI_sva: pool returned IPv4=%s, IPv6=%s",
1479 : "(Not enabled)"),
1481 ? print_in6_addr(remote_ipv6, 0, &gc)
1482 : "(Not enabled)"));
1483
1485 {
1486 /* set push_ifconfig_remote_netmask from pool ifconfig address(es) */
1487 mi->context.c2.push_ifconfig_local = remote;
1488 if (tunnel_type == DEV_TYPE_TAP
1489 || (tunnel_type == DEV_TYPE_TUN && tunnel_topology == TOP_SUBNET))
1490 {
1494 {
1497 }
1498 }
1499 else if (tunnel_type == DEV_TYPE_TUN)
1500 {
1501 if (tunnel_topology == TOP_P2P)
1502 {
1504 }
1505 else if (tunnel_topology == TOP_NET30)
1506 {
1508 }
1509 }
1510
1512 {
1513 mi->context.c2.push_ifconfig_defined = true;
1514 }
1515 else
1516 {
1518 "MULTI: no --ifconfig-pool netmask parameter is available to push to %s",
1519 multi_instance_string(mi, false, &gc));
1520 }
1521 }
1522
1524 {
1525 mi->context.c2.push_ifconfig_ipv6_local = remote_ipv6;
1530 }
1531 }
1532 else
1533 {
1534 msg(D_MULTI_ERRORS, "MULTI: no free --ifconfig-pool addresses are available");
1535 }
1536 }
1537
1538 /* IPv6 push_ifconfig is a bit problematic - since IPv6 shares the
1539 * pool handling with IPv4, the combination "static IPv4, dynamic IPv6"
1540 * will fail (because no pool will be allocated in this case).
1541 * OTOH, this doesn't make too much sense in reality - and the other
1542 * way round ("dynamic IPv4, static IPv6") or "both static" makes sense
1543 * -> and so it's implemented right now
1544 */
1546 {
1551
1552 msg(M_INFO, "MULTI_sva: push_ifconfig_ipv6 %s/%d",
1555 }
1556
1557 gc_free(&gc);
1558}
1559
1560/*
1561 * Set virtual address environmental variables.
1562 */
1563static void
1565{
1566 setenv_del(mi->context.c2.es, "ifconfig_pool_local_ip");
1567 setenv_del(mi->context.c2.es, "ifconfig_pool_remote_ip");
1568 setenv_del(mi->context.c2.es, "ifconfig_pool_netmask");
1569
1571 {
1572 const int tunnel_type = TUNNEL_TYPE(mi->context.c1.tuntap);
1573 const int tunnel_topology = TUNNEL_TOPOLOGY(mi->context.c1.tuntap);
1574
1575 setenv_in_addr_t(mi->context.c2.es, "ifconfig_pool_remote_ip",
1577
1578 if (tunnel_type == DEV_TYPE_TAP
1579 || (tunnel_type == DEV_TYPE_TUN && tunnel_topology == TOP_SUBNET))
1580 {
1581 setenv_in_addr_t(mi->context.c2.es, "ifconfig_pool_netmask",
1583 }
1584 else if (tunnel_type == DEV_TYPE_TUN)
1585 {
1586 setenv_in_addr_t(mi->context.c2.es, "ifconfig_pool_local_ip",
1588 }
1589 }
1590
1591 setenv_del(mi->context.c2.es, "ifconfig_pool_local_ip6");
1592 setenv_del(mi->context.c2.es, "ifconfig_pool_remote_ip6");
1593 setenv_del(mi->context.c2.es, "ifconfig_pool_ip6_netbits");
1594
1596 {
1597 setenv_in6_addr(mi->context.c2.es, "ifconfig_pool_remote",
1599 setenv_in6_addr(mi->context.c2.es, "ifconfig_pool_local",
1601 setenv_int(mi->context.c2.es, "ifconfig_pool_ip6_netbits",
1603 }
1604}
1605
1606/*
1607 * Called after client-connect script is called
1608 */
1609static void
1610multi_client_connect_post(struct multi_context *m, struct multi_instance *mi, const char *dc_file,
1611 uint64_t *option_types_found)
1612{
1613 /* Did script generate a dynamic config file? */
1614 if (platform_test_file(dc_file))
1615 {
1617 CLIENT_CONNECT_OPT_MASK, option_types_found, mi->context.c2.es);
1618
1619 /*
1620 * If the --client-connect script generates a config file
1621 * with an --ifconfig-push directive, it will override any
1622 * --ifconfig-push directive from the --client-config-dir
1623 * directory or any --ifconfig-pool dynamic address.
1624 */
1627 }
1628}
1629
1630#ifdef ENABLE_PLUGIN
1631
1632/*
1633 * Called after client-connect plug-in is called
1634 */
1635static void
1637 const struct plugin_return *pr, uint64_t *option_types_found)
1638{
1639 struct plugin_return config;
1640
1641 plugin_return_get_column(pr, &config, "config");
1642
1643 /* Did script generate a dynamic config file? */
1644 if (plugin_return_defined(&config))
1645 {
1646 int i;
1647 for (i = 0; i < config.n; ++i)
1648 {
1649 if (config.list[i] && config.list[i]->value)
1650 {
1651 options_string_import(&mi->context.options, config.list[i]->value,
1653 option_types_found, mi->context.c2.es);
1654 }
1655 }
1656
1657 /*
1658 * If the --client-connect script generates a config file
1659 * with an --ifconfig-push directive, it will override any
1660 * --ifconfig-push directive from the --client-config-dir
1661 * directory or any --ifconfig-pool dynamic address.
1662 */
1665 }
1666}
1667
1668#endif /* ifdef ENABLE_PLUGIN */
1669
1670
1671/*
1672 * Called to load management-derived client-connect config
1673 */
1675multi_client_connect_mda(struct multi_context *m, struct multi_instance *mi, bool deferred,
1676 uint64_t *option_types_found)
1677{
1678 /* We never return CC_RET_DEFERRED */
1679 ASSERT(!deferred);
1681#ifdef ENABLE_MANAGEMENT
1682 if (mi->cc_config)
1683 {
1684 struct buffer_entry *be;
1685 for (be = mi->cc_config->head; be != NULL; be = be->next)
1686 {
1687 const char *opt = BSTR(&be->buf);
1689 CLIENT_CONNECT_OPT_MASK, option_types_found, mi->context.c2.es);
1690 }
1691
1692 /*
1693 * If the --client-connect script generates a config file
1694 * with an --ifconfig-push directive, it will override any
1695 * --ifconfig-push directive from the --client-config-dir
1696 * directory or any --ifconfig-pool dynamic address.
1697 */
1700
1701 ret = CC_RET_SUCCEEDED;
1702 }
1703#endif /* ifdef ENABLE_MANAGEMENT */
1704 return ret;
1705}
1706
1707static void
1709{
1710 struct gc_arena gc = gc_new();
1711
1712 /* setenv incoming cert common name for script */
1713 setenv_str(mi->context.c2.es, "common_name", tls_common_name(mi->context.c2.tls_multi, true));
1714
1715 /* setenv client real IP address */
1717
1718 /* setenv client virtual IP address */
1720
1721 /* setenv connection time */
1722 {
1723 const char *created_ascii = time_string(mi->created, 0, false, &gc);
1724 setenv_str(mi->context.c2.es, "time_ascii", created_ascii);
1725 setenv_long_long(mi->context.c2.es, "time_unix", mi->created);
1726 }
1727
1728 gc_free(&gc);
1729}
1730
1737static bool
1739{
1740 struct tls_multi *tls_multi = c->c2.tls_multi;
1741 const char *const peer_info = tls_multi->peer_info;
1742 struct options *o = &c->options;
1743
1744
1745 unsigned int proto = extract_iv_proto(peer_info);
1746 if (proto & IV_PROTO_DATA_V2)
1747 {
1748 tls_multi->use_peer_id = true;
1749 o->use_peer_id = true;
1750 }
1751 else if (dco_enabled(o))
1752 {
1753 msg(M_INFO, "Client does not support DATA_V2. Data channel offloading "
1754 "requires DATA_V2. Dropping client.");
1755 auth_set_client_reason(tls_multi, "Data channel negotiation "
1756 "failed (missing DATA_V2)");
1757 return false;
1758 }
1759
1760 /* Print a warning if we detect the client being in P2P mode and will
1761 * not accept our pushed ciphers */
1762 if (proto & IV_PROTO_NCP_P2P)
1763 {
1764 msg(M_WARN, "Note: peer reports running in P2P mode (no --pull/--client "
1765 "option). It will not negotiate ciphers with this server. "
1766 "Expect this connection to fail.");
1767 }
1768
1769 if (proto & IV_PROTO_REQUEST_PUSH)
1770 {
1771 c->c2.push_request_received = true;
1772 }
1773
1774 if (proto & IV_PROTO_TLS_KEY_EXPORT)
1775 {
1777 }
1778 else if (o->force_key_material_export)
1779 {
1780 msg(M_INFO, "PUSH: client does not support TLS Keying Material "
1781 "Exporters but --force-tls-key-material-export is enabled.");
1782 auth_set_client_reason(tls_multi, "Client incompatible with this "
1783 "server. Keying Material Exporters (RFC 5705) "
1784 "support missing. Upgrade to a client that "
1785 "supports this feature (OpenVPN 2.6.0+).");
1786 return false;
1787 }
1788 if (proto & IV_PROTO_DYN_TLS_CRYPT)
1789 {
1791 }
1792
1793 if (proto & IV_PROTO_CC_EXIT_NOTIFY)
1794 {
1796 }
1797
1798 /* Select cipher if client supports Negotiable Crypto Parameters */
1799
1800 /* if we have already created our key, we cannot *change* our own
1801 * cipher -> so log the fact and push the "what we have now" cipher
1802 * (so the client is always told what we expect it to use)
1803 */
1805 {
1806 msg(M_INFO,
1807 "PUSH: client wants to negotiate cipher (NCP), but "
1808 "server has already generated data channel keys, "
1809 "re-sending previously negotiated cipher '%s'",
1810 o->ciphername);
1811 return true;
1812 }
1813
1814 /*
1815 * Push the first cipher from --data-ciphers to the client that
1816 * the client announces to be supporting.
1817 */
1818 const char *push_cipher =
1820 if (push_cipher)
1821 {
1822 /* Enable epoch data key format if supported and AEAD cipher in use */
1824 && cipher_kt_mode_aead(push_cipher))
1825 {
1827 }
1828
1829 o->ciphername = push_cipher;
1830 return true;
1831 }
1832
1833 /* NCP cipher negotiation failed. Try to figure out why exactly it
1834 * failed and give good error messages and potentially do a fallback
1835 * for non NCP clients */
1836 struct gc_arena gc = gc_new();
1837 bool ret = false;
1838
1839 const char *peer_ciphers = tls_peer_ncp_list(peer_info, &gc);
1840 /* If we are in a situation where we know the client ciphers, there is no
1841 * reason to fall back to a cipher that will not be accepted by the other
1842 * side, in this situation we fail the auth*/
1843 if (strlen(peer_ciphers) > 0)
1844 {
1845 msg(M_INFO,
1846 "PUSH: No common cipher between server and client. "
1847 "Server data-ciphers: '%s'%s, client supported ciphers '%s'",
1848 o->ncp_ciphers_conf, ncp_expanded_ciphers(o, &gc), peer_ciphers);
1849 }
1850 else if (tls_multi->remote_ciphername)
1851 {
1852 msg(M_INFO,
1853 "PUSH: No common cipher between server and client. "
1854 "Server data-ciphers: '%s'%s, client supports cipher '%s'",
1856 }
1857 else
1858 {
1859 msg(M_INFO, "PUSH: No NCP or OCC cipher data received from peer.");
1860
1861 if (o->enable_ncp_fallback)
1862 {
1863 msg(M_INFO,
1864 "Using data channel cipher '%s' since "
1865 "--data-ciphers-fallback is set.",
1866 o->ciphername);
1867 ret = true;
1868 }
1869 else
1870 {
1871 msg(M_INFO, "Use --data-ciphers-fallback with the cipher the "
1872 "client is using if you want to allow the client to connect");
1873 }
1874 }
1875 if (!ret)
1876 {
1877 auth_set_client_reason(tls_multi, "Data channel cipher negotiation "
1878 "failed (no shared cipher)");
1879 }
1880
1881 gc_free(&gc);
1882 return ret;
1883}
1884
1889static void
1891{
1893 if (!ccs->deferred_ret_file)
1894 {
1895 return;
1896 }
1897
1898 setenv_del(mi->context.c2.es, "client_connect_deferred_file");
1900 {
1901 msg(D_MULTI_ERRORS, "MULTI: problem deleting temporary file: %s", ccs->deferred_ret_file);
1902 }
1903 free(ccs->deferred_ret_file);
1904 ccs->deferred_ret_file = NULL;
1905}
1906
1914static bool
1916{
1918 struct gc_arena gc = gc_new();
1919 const char *fn;
1920
1921 /* Delete file if it already exists */
1923
1925 if (!fn)
1926 {
1927 gc_free(&gc);
1928 return false;
1929 }
1930 ccs->deferred_ret_file = string_alloc(fn, NULL);
1931
1932 setenv_str(mi->context.c2.es, "client_connect_deferred_file", ccs->deferred_ret_file);
1933
1934 gc_free(&gc);
1935 return true;
1936}
1937
1946static enum client_connect_return
1948{
1949 const struct client_connect_defer_state *ccs = &(mi->client_connect_defer_state);
1950 FILE *fp = fopen(ccs->deferred_ret_file, "r");
1951 if (!fp)
1952 {
1953 return CC_RET_SKIPPED;
1954 }
1955
1957 const int c = fgetc(fp);
1958 switch (c)
1959 {
1960 case '0':
1961 ret = CC_RET_FAILED;
1962 break;
1963
1964 case '1':
1965 ret = CC_RET_SUCCEEDED;
1966 break;
1967
1968 case '2':
1969 ret = CC_RET_DEFERRED;
1970 break;
1971
1972 case EOF:
1973 if (feof(fp))
1974 {
1975 ret = CC_RET_SKIPPED;
1976 break;
1977 }
1978
1979 /* Not EOF but other error -> fall through to error state */
1980 default:
1981 /* We received an unknown/unexpected value. Assume failure. */
1982 msg(M_WARN, "WARNING: Unknown/unexpected value in deferred "
1983 "client-connect resultfile");
1984 ret = CC_RET_FAILED;
1985 }
1986 fclose(fp);
1987
1988 return ret;
1989}
1990
1996static void
1998{
2000 if (ccs->config_file)
2001 {
2002 setenv_del(mi->context.c2.es, "client_connect_config_file");
2003 if (!platform_unlink(ccs->config_file))
2004 {
2005 msg(D_MULTI_ERRORS, "MULTI: problem deleting temporary file: %s", ccs->config_file);
2006 }
2007 free(ccs->config_file);
2008 ccs->config_file = NULL;
2009 }
2010}
2011
2019static bool
2021{
2023 struct gc_arena gc = gc_new();
2024 const char *fn;
2025
2026 if (ccs->config_file)
2027 {
2029 }
2030
2032 if (!fn)
2033 {
2034 gc_free(&gc);
2035 return false;
2036 }
2037 ccs->config_file = string_alloc(fn, NULL);
2038
2039 setenv_str(mi->context.c2.es, "client_connect_config_file", ccs->config_file);
2040
2041 gc_free(&gc);
2042 return true;
2043}
2044
2045static enum client_connect_return
2047 bool deferred, uint64_t *option_types_found)
2048{
2050#ifdef ENABLE_PLUGIN
2051 ASSERT(m);
2052 ASSERT(mi);
2053 ASSERT(option_types_found);
2055
2056 /* deprecated callback, use a file for passing back return info */
2057 if (plugin_defined(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_CONNECT))
2058 {
2059 struct argv argv = argv_new();
2060 int call;
2061
2062 if (!deferred)
2063 {
2064 call = OPENVPN_PLUGIN_CLIENT_CONNECT;
2066 {
2067 ret = CC_RET_FAILED;
2068 goto cleanup;
2069 }
2070 }
2071 else
2072 {
2073 call = OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER;
2074 /* the initial call should have created these files */
2075 ASSERT(ccs->config_file);
2077 }
2078
2079 argv_printf(&argv, "%s", ccs->config_file);
2080 int plug_ret = plugin_call(mi->context.plugins, call, &argv, NULL, mi->context.c2.es);
2081 if (plug_ret == OPENVPN_PLUGIN_FUNC_SUCCESS)
2082 {
2083 ret = CC_RET_SUCCEEDED;
2084 }
2085 else if (plug_ret == OPENVPN_PLUGIN_FUNC_DEFERRED)
2086 {
2087 ret = CC_RET_DEFERRED;
2093 }
2094 else
2095 {
2096 msg(M_WARN, "WARNING: client-connect plugin call failed");
2097 ret = CC_RET_FAILED;
2098 }
2099
2100
2106 int file_ret = ccs_test_deferred_ret_file(mi);
2107
2108 if (file_ret == CC_RET_FAILED)
2109 {
2110 ret = CC_RET_FAILED;
2111 }
2112 else if (ret == CC_RET_SUCCEEDED && file_ret == CC_RET_DEFERRED)
2113 {
2114 ret = CC_RET_DEFERRED;
2115 }
2116
2117 /* if we still think we have succeeded, do postprocessing */
2118 if (ret == CC_RET_SUCCEEDED)
2119 {
2120 multi_client_connect_post(m, mi, ccs->config_file, option_types_found);
2121 }
2122cleanup:
2123 argv_free(&argv);
2124
2125 if (ret != CC_RET_DEFERRED)
2126 {
2129 }
2130 }
2131#endif /* ifdef ENABLE_PLUGIN */
2132 return ret;
2133}
2134
2135static enum client_connect_return
2137 bool deferred, uint64_t *option_types_found)
2138{
2140#ifdef ENABLE_PLUGIN
2141 ASSERT(m);
2142 ASSERT(mi);
2143 ASSERT(option_types_found);
2144
2145 int call = deferred ? OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER_V2 : OPENVPN_PLUGIN_CLIENT_CONNECT_V2;
2146 /* V2 callback, use a plugin_return struct for passing back return info */
2147 if (plugin_defined(mi->context.plugins, call))
2148 {
2149 struct plugin_return pr;
2150
2151 plugin_return_init(&pr);
2152
2153 int plug_ret = plugin_call(mi->context.plugins, call, NULL, &pr, mi->context.c2.es);
2154 if (plug_ret == OPENVPN_PLUGIN_FUNC_SUCCESS)
2155 {
2156 multi_client_connect_post_plugin(m, mi, &pr, option_types_found);
2157 ret = CC_RET_SUCCEEDED;
2158 }
2159 else if (plug_ret == OPENVPN_PLUGIN_FUNC_DEFERRED)
2160 {
2161 ret = CC_RET_DEFERRED;
2162 if (!(plugin_defined(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER_V2)))
2163 {
2164 msg(M_WARN, "A plugin that defers from the "
2165 "OPENVPN_PLUGIN_CLIENT_CONNECT_V2 call must also "
2166 "declare support for "
2167 "OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER_V2");
2168 ret = CC_RET_FAILED;
2169 }
2170 }
2171 else
2172 {
2173 msg(M_WARN, "WARNING: client-connect-v2 plugin call failed");
2174 ret = CC_RET_FAILED;
2175 }
2176
2177
2178 plugin_return_free(&pr);
2179 }
2180#endif /* ifdef ENABLE_PLUGIN */
2181 return ret;
2182}
2183
2184static enum client_connect_return
2186 uint64_t *option_types_found)
2187{
2188 ASSERT(mi);
2189 ASSERT(option_types_found);
2190 const struct client_connect_defer_state *ccs = &(mi->client_connect_defer_state);
2192
2194
2195 if (ret == CC_RET_SKIPPED)
2196 {
2197 /*
2198 * Skipped and deferred are equivalent in this context.
2199 * skipped means that the called program has not yet
2200 * written a return status implicitly needing more time
2201 * while deferred is the explicit notification that it
2202 * needs more time
2203 */
2204 ret = CC_RET_DEFERRED;
2205 }
2206
2207 if (ret == CC_RET_SUCCEEDED)
2208 {
2212 }
2213 if (ret == CC_RET_FAILED)
2214 {
2215 msg(M_INFO, "MULTI: deferred --client-connect script returned CC_RET_FAILED");
2218 }
2219 return ret;
2220}
2221
2225static enum client_connect_return
2227 uint64_t *option_types_found)
2228{
2229 if (deferred)
2230 {
2232 }
2233 ASSERT(m);
2234 ASSERT(mi);
2235
2238
2240 {
2241 struct argv argv = argv_new();
2242 struct gc_arena gc = gc_new();
2243
2244 setenv_str(mi->context.c2.es, "script_type", "client-connect");
2245
2247 {
2248 ret = CC_RET_FAILED;
2249 goto cleanup;
2250 }
2251
2253 argv_printf_cat(&argv, "%s", ccs->config_file);
2254
2255 if (openvpn_run_script(&argv, mi->context.c2.es, 0, "--client-connect"))
2256 {
2258 {
2259 ret = CC_RET_DEFERRED;
2260 }
2261 else
2262 {
2263 multi_client_connect_post(m, mi, ccs->config_file, option_types_found);
2264 ret = CC_RET_SUCCEEDED;
2265 }
2266 }
2267 else
2268 {
2269 ret = CC_RET_FAILED;
2270 }
2271cleanup:
2272 if (ret != CC_RET_DEFERRED)
2273 {
2276 }
2277 argv_free(&argv);
2278 gc_free(&gc);
2279 }
2280 return ret;
2281}
2282
2283static bool
2285 struct gc_arena *gc)
2286{
2287 if (!dco_enabled(&mi->context.options))
2288 {
2289 /* DCO not enabled, nothing to do, return sucess */
2290 return true;
2291 }
2292 int ret = dco_multi_add_new_peer(m, mi);
2293 if (ret < 0)
2294 {
2295 msg(D_DCO, "Cannot add peer to DCO for %s: %s (%d)", multi_instance_string(mi, false, gc),
2296 strerror(-ret), ret);
2297 return false;
2298 }
2299
2300 return true;
2301}
2302
2306static bool
2308{
2309 struct frame *frame_fragment = NULL;
2310#ifdef ENABLE_FRAGMENT
2311 if (c->options.ce.fragment)
2312 {
2313 frame_fragment = &c->c2.frame_fragment;
2314 }
2315#endif
2318 frame_fragment, get_link_socket_info(c),
2319 &c->c1.tuntap->dco))
2320 {
2321 msg(D_TLS_ERRORS, "TLS Error: initializing data channel failed");
2322 register_signal(c->sig, SIGUSR1, "process-push-msg-failed");
2323 return false;
2324 }
2325
2326 return true;
2327}
2328
2329static void
2331 const uint64_t option_types_found)
2332{
2333 ASSERT(m);
2334 ASSERT(mi);
2335
2336 struct gc_arena gc = gc_new();
2337 /*
2338 * Process sourced options.
2339 */
2340 do_deferred_options(&mi->context, option_types_found, false);
2341
2342 /*
2343 * make sure we got ifconfig settings from somewhere
2344 */
2346 {
2348 "MULTI: no dynamic or static remote "
2349 "--ifconfig address is available for %s",
2350 multi_instance_string(mi, false, &gc));
2351 }
2352
2353 /*
2354 * make sure that ifconfig settings comply with constraints
2355 */
2357 {
2358 const char *ifconfig_constraint_network =
2360 const char *ifconfig_constraint_netmask =
2362
2363 /* JYFIXME -- this should cause the connection to fail */
2365 "MULTI ERROR: primary virtual IP for %s (%s) "
2366 "violates tunnel network/netmask constraint (%s/%s)",
2367 multi_instance_string(mi, false, &gc),
2369 ifconfig_constraint_network, ifconfig_constraint_netmask);
2370 }
2371
2372 /* set our client's VPN endpoint for status reporting purposes */
2375
2376 /* set context-level authentication flag */
2378
2379 /* Since dco-win maintains iroute routing table (subnet -> peer),
2380 * peer must be added before iroutes. For other platforms it doesn't matter. */
2381
2382 /* authentication complete, calculate dynamic client specific options */
2384 {
2386 }
2387 /* only continue if setting protocol options worked */
2388 else if (!multi_client_setup_dco_initial(m, mi, &gc))
2389 {
2391 }
2392 /* Generate data channel keys only if setting protocol options
2393 * and DCO initial setup has not failed */
2395 {
2397 }
2398
2399 /* dco peer has been added, it is now safe for Windows to add iroutes */
2400
2401 /*
2402 * For routed tunnels, set up internal route to endpoint
2403 * plus add all iroute routes.
2404 */
2406 {
2408 {
2410 msg(D_MULTI_LOW, "MULTI: primary virtual IP for %s: %s",
2411 multi_instance_string(mi, false, &gc),
2413 }
2414
2416 {
2418 /* TODO: find out where addresses are "unlearned"!! */
2419 const char *ifconfig_local_ipv6 =
2421 msg(D_MULTI_LOW, "MULTI: primary virtual IPv6 for %s: %s",
2422 multi_instance_string(mi, false, &gc), ifconfig_local_ipv6);
2423 }
2424
2425 /* add routes locally, pointing to new client, if
2426 * --iroute options have been specified */
2427 multi_add_iroutes(m, mi);
2428
2429 /*
2430 * iroutes represent subnets which are "owned" by a particular
2431 * client. Therefore, do not actually push a route to a client
2432 * if it matches one of the client's iroutes.
2433 */
2435 }
2436 else if (mi->context.options.iroutes)
2437 {
2439 "MULTI: --iroute options rejected for %s -- iroute "
2440 "only works with tun-style tunnels",
2441 multi_instance_string(mi, false, &gc));
2442 }
2443
2444 /* send push reply if ready */
2446 {
2448 }
2449 gc_free(&gc);
2450}
2451
2452static void
2454{
2455 ASSERT(mi->context.c1.tuntap);
2456 /*
2457 * lock down the common name and cert hashes so they can't change
2458 * during future TLS renegotiations
2459 */
2462
2463 /* generate a msg() prefix for this client instance */
2464 generate_prefix(mi);
2465
2466 /* delete instances of previous clients with same common-name */
2467 if (!mi->context.options.duplicate_cn)
2468 {
2469 multi_delete_dup(m, mi);
2470 }
2471
2472 /* reset pool handle to null */
2473 mi->vaddr_handle = -1;
2474
2475 /* do --client-connect setenvs */
2477
2479}
2480
2481static bool
2482multi_check_dest_addr_allowed(struct multi_context *m, struct multi_instance *mi, struct mroute_addr *real);
2483
2489static enum client_connect_return
2491 bool deferred, uint64_t *option_types_found)
2492{
2493 /* If the address is already taken up by another client we fail the new
2494 * connection */
2495 if (!multi_check_dest_addr_allowed(m, mi, &mi->real))
2496 {
2498 "MULTI: client IP address and port already assigned to another "
2499 "client, terminating connection");
2500 return CC_RET_FAILED;
2501 }
2502
2503 ASSERT(!mi->did_real_hash);
2504 ASSERT(hash_add(m->hash, &mi->real, mi, false));
2505 mi->did_real_hash = true;
2506 return CC_RET_SUCCEEDED;
2507}
2508
2515static enum client_connect_return
2517 bool deferred, uint64_t *option_types_found)
2518{
2519#ifdef USE_COMP
2520 struct options *o = &mi->context.options;
2521 const char *const peer_info = mi->context.c2.tls_multi->peer_info;
2522
2524 {
2525 if (peer_info && strstr(peer_info, "IV_COMP_STUBv2=1"))
2526 {
2527 push_option(o, "compress stub-v2", M_USAGE);
2528 }
2529 else
2530 {
2531 /* Client is old and does not support STUBv2 but since it
2532 * announced comp-lzo via OCC we assume it uses comp-lzo, so
2533 * switch to that and push the uncompressed variant. */
2534 push_option(o, "comp-lzo no", M_USAGE);
2535 o->comp.alg = COMP_ALG_STUB;
2536 *option_types_found |= OPT_P_COMP;
2537 }
2538 }
2539#endif
2540 return CC_RET_SUCCEEDED;
2541}
2542
2547static enum client_connect_return
2549 uint64_t *option_types_found)
2550{
2551 /* Since we never return a CC_RET_DEFERRED, this indicates a serious
2552 * problem */
2553 ASSERT(!deferred);
2556 {
2557 struct gc_arena gc = gc_new();
2558 const char *ccd_file = NULL;
2559
2560 const char *ccd_client =
2562 tls_common_name(mi->context.c2.tls_multi, false), &gc);
2563
2564 const char *ccd_default =
2566
2567
2568 /* try common-name file */
2569 if (platform_test_file(ccd_client))
2570 {
2571 ccd_file = ccd_client;
2572 }
2573 /* try default file */
2574 else if (platform_test_file(ccd_default))
2575 {
2576 ccd_file = ccd_default;
2577 }
2578
2579 if (ccd_file)
2580 {
2582 CLIENT_CONNECT_OPT_MASK, option_types_found, mi->context.c2.es);
2583 /*
2584 * Select a virtual address from either --ifconfig-push in
2585 * --client-config-dir file or --ifconfig-pool.
2586 */
2588
2590
2591 ret = CC_RET_SUCCEEDED;
2592 }
2593 gc_free(&gc);
2594 }
2595 return ret;
2596}
2597
2599 struct multi_context *m, struct multi_instance *mi, bool from_deferred,
2600 uint64_t *option_types_found);
2601
2612
2617static bool
2619{
2620 struct tls_multi *multi = mi->context.c2.tls_multi;
2621 const struct options *options = &mi->context.options;
2622 struct tls_session *session = &multi->session[TM_ACTIVE];
2623
2624 if (!multi->locked_username)
2625 {
2626 msg(D_MULTI_ERRORS, "MULTI: Ignoring override-username as no "
2627 "user/password method is enabled. Enable "
2628 "--management-client-auth, --auth-user-pass-verify, or a "
2629 "plugin with user/password verify capability.");
2630 return false;
2631 }
2632
2633 if (!multi->locked_original_username
2634 && strcmp(multi->locked_username, options->override_username) != 0)
2635 {
2636 /* Check if the username length is acceptable */
2638 {
2639 return false;
2640 }
2641
2643 multi->locked_username = strdup(options->override_username);
2644
2645 /* Override also the common name if username should be set as common
2646 * name */
2647 if ((session->opt->ssl_flags & SSLF_USERNAME_AS_COMMON_NAME))
2648 {
2650 free(multi->locked_cn);
2651 multi->locked_cn = NULL;
2652 tls_lock_common_name(multi);
2653 }
2654
2655 /* Regenerate the auth-token if enabled */
2656 if (multi->auth_token_initial)
2657 {
2658 struct user_pass up;
2659 CLEAR(up);
2660 strncpynt(up.username, multi->locked_username, sizeof(up.username));
2661
2662 generate_auth_token(&up, multi);
2663 }
2664
2666 "MULTI: Note, override-username changes username "
2667 "from '%s' to '%s'",
2669 }
2670 return true;
2671}
2672
2673/*
2674 * Called as soon as the SSL/TLS connection is authenticated.
2675 *
2676 * Will collect the client specific configuration from the different
2677 * sources like ccd files, connect plugins and management interface.
2678 *
2679 * This method starts with cas_context CAS_PENDING and will move the
2680 * state machine to either CAS_SUCCEEDED on success or
2681 * CAS_FAILED/CAS_PARTIAL on failure.
2682 *
2683 * Instance-specific directives to be processed (CLIENT_CONNECT_OPT_MASK)
2684 * include:
2685 *
2686 * iroute start-ip end-ip
2687 * ifconfig-push local remote-netmask
2688 * push
2689 *
2690 *
2691 */
2692static void
2694{
2695 /* We are only called for the CAS_PENDING_x states, so we
2696 * can ignore other states here */
2697 bool from_deferred = (mi->context.c2.tls_multi->multi_state != CAS_PENDING);
2698
2699 int *cur_handler_index = &mi->client_connect_defer_state.cur_handler_index;
2700 uint64_t *option_types_found = &mi->client_connect_defer_state.option_types_found;
2701
2702 /* We are called for the first time */
2703 if (!from_deferred)
2704 {
2705 *cur_handler_index = 0;
2706 *option_types_found = 0;
2707 /* Initially we have no handler that has returned a result */
2709
2711 }
2712
2713 bool cc_succeeded = true;
2714
2715 while (cc_succeeded && client_connect_handlers[*cur_handler_index] != NULL)
2716 {
2717 enum client_connect_return ret;
2718 ret = client_connect_handlers[*cur_handler_index](m, mi, from_deferred, option_types_found);
2719
2720 from_deferred = false;
2721
2722 switch (ret)
2723 {
2724 case CC_RET_SUCCEEDED:
2725 /*
2726 * Remember that we already had at least one handler
2727 * returning a result should we go to into deferred state
2728 */
2729 mi->context.c2.tls_multi->multi_state = CAS_PENDING_DEFERRED_PARTIAL;
2730 break;
2731
2732 case CC_RET_SKIPPED:
2733 /*
2734 * Move on with the next handler without modifying any
2735 * other state
2736 */
2737 break;
2738
2739 case CC_RET_DEFERRED:
2740 /*
2741 * we already set multi_status to DEFERRED_RESULT or
2742 * DEFERRED_NO_RESULT. We just return
2743 * from the function as having multi_status
2744 */
2745 return;
2746
2747 case CC_RET_FAILED:
2748 /*
2749 * One handler failed. We abort the chain and set the final
2750 * result to failed
2751 */
2752 cc_succeeded = false;
2753 break;
2754
2755 default:
2756 ASSERT(0);
2757 }
2758
2759 /*
2760 * Check for "disable" directive in client-config-dir file
2761 * or config file generated by --client-connect script.
2762 */
2763 if (mi->context.options.disable)
2764 {
2765 msg(D_MULTI_ERRORS, "MULTI: client has been rejected due to "
2766 "'disable' directive");
2767 cc_succeeded = false;
2768 }
2769
2770 (*cur_handler_index)++;
2771 }
2772
2774 {
2775 if (!override_locked_username(mi))
2776 {
2777 cc_succeeded = false;
2778 }
2779 }
2780
2781 /* Check if we have forbidding options in the current mode */
2782 if (dco_enabled(&mi->context.options)
2784 {
2785 msg(D_MULTI_ERRORS, "MULTI: client has been rejected due to incompatible DCO options");
2786 cc_succeeded = false;
2787 }
2788
2790 {
2791 msg(D_MULTI_ERRORS, "MULTI: client has been rejected due to invalid compression options");
2792 cc_succeeded = false;
2793 }
2794
2795 if (cc_succeeded)
2796 {
2797 multi_client_connect_late_setup(m, mi, *option_types_found);
2798 }
2799 else
2800 {
2801 /* run the disconnect script if we had a connect script that
2802 * did not fail */
2804 {
2806 }
2807
2809 }
2810
2811 /* increment number of current authenticated clients */
2812 ++m->n_clients;
2813 --mi->n_clients_delta;
2814
2815#ifdef ENABLE_MANAGEMENT
2816 if (management)
2817 {
2819 mi->context.c2.es);
2820 }
2821#endif
2822}
2823
2824#ifdef ENABLE_ASYNC_PUSH
2825/*
2826 * Called when inotify event is fired, which happens when acf
2827 * or connect-status file is closed or deleted.
2828 * Continues authentication and sends push_reply
2829 * (or be deferred again by client-connect)
2830 */
2831void
2832multi_process_file_closed(struct multi_context *m, const unsigned int mpp_flags)
2833{
2834 char buffer[INOTIFY_EVENT_BUFFER_SIZE];
2835 ssize_t buffer_i = 0;
2836 ssize_t r = read(m->top.c2.inotify_fd, buffer, INOTIFY_EVENT_BUFFER_SIZE);
2837 if (r < 0)
2838 {
2839 msg(M_WARN | M_ERRNO, "MULTI: multi_process_file_closed error");
2840 return;
2841 }
2842
2843 while (buffer_i < r)
2844 {
2845 /* parse inotify events */
2846 struct inotify_event *pevent = (struct inotify_event *)&buffer[buffer_i];
2847 size_t event_size = sizeof(struct inotify_event) + pevent->len;
2848 buffer_i += event_size;
2849
2850 msg(D_MULTI_DEBUG, "MULTI: modified fd %d, mask %d", pevent->wd, pevent->mask);
2851
2852 struct multi_instance *mi =
2853 hash_lookup(m->inotify_watchers, (void *)(uintptr_t)pevent->wd);
2854
2855 if (pevent->mask & IN_CLOSE_WRITE)
2856 {
2857 if (mi)
2858 {
2859 /* continue authentication, perform NCP negotiation and send push_reply */
2860 multi_process_post(m, mi, mpp_flags);
2861 }
2862 else
2863 {
2864 msg(D_MULTI_ERRORS, "MULTI: multi_instance not found!");
2865 }
2866 }
2867 else if (pevent->mask & IN_IGNORED)
2868 {
2869 /* this event is _always_ fired when watch is removed or file is deleted */
2870 if (mi)
2871 {
2872 hash_remove(m->inotify_watchers, (void *)(uintptr_t)pevent->wd);
2873 mi->inotify_watch = -1;
2874 }
2875 }
2876 else
2877 {
2878 msg(D_MULTI_ERRORS, "MULTI: unknown mask %d", pevent->mask);
2879 }
2880 }
2881}
2882#endif /* ifdef ENABLE_ASYNC_PUSH */
2883
2884/*
2885 * Add a mbuf buffer to a particular
2886 * instance.
2887 */
2888static void
2889multi_add_mbuf(struct multi_context *m, struct multi_instance *mi, struct mbuf_buffer *mb)
2890{
2891 if (multi_output_queue_ready(m, mi))
2892 {
2893 struct mbuf_item item;
2894 item.buffer = mb;
2895 item.instance = mi;
2896 mbuf_add_item(m->mbuf, &item);
2897 }
2898 else
2899 {
2900 msg(D_MULTI_DROPPED, "MULTI: packet dropped due to output saturation (multi_add_mbuf)");
2901 }
2902}
2903
2904/*
2905 * Add a packet to a client instance output queue.
2906 */
2907static inline void
2908multi_unicast(struct multi_context *m, const struct buffer *buf, struct multi_instance *mi)
2909{
2910 struct mbuf_buffer *mb;
2911
2912 if (BLEN(buf) > 0)
2913 {
2914 mb = mbuf_alloc_buf(buf);
2915 mb->flags = MF_UNICAST;
2916 multi_add_mbuf(m, mi, mb);
2917 mbuf_free_buf(mb);
2918 }
2919}
2920
2921/*
2922 * Broadcast a packet to all clients.
2923 */
2924static void
2925multi_bcast(struct multi_context *m, const struct buffer *buf,
2926 const struct multi_instance *sender_instance, uint16_t vid)
2927{
2928 struct mbuf_buffer *mb;
2929
2930 if (BLEN(buf) > 0)
2931 {
2932#ifdef MULTI_DEBUG_EVENT_LOOP
2933 printf("BCAST len=%d\n", BLEN(buf));
2934#endif
2935 mb = mbuf_alloc_buf(buf);
2936
2937 for (uint32_t i = 0; i <= m->max_peerid; i++)
2938 {
2939 struct multi_instance *mi = m->instances[i];
2940
2941 if (mi && mi != sender_instance && !mi->halt)
2942 {
2943 if (vid != 0 && vid != mi->context.options.vlan_pvid)
2944 {
2945 continue;
2946 }
2947 multi_add_mbuf(m, mi, mb);
2948 }
2949 }
2950 mbuf_free_buf(mb);
2951 }
2952}
2953
2954/*
2955 * Given a time delta, indicating that we wish to be
2956 * awoken by the scheduler at time now + delta, figure
2957 * a sigma parameter (in microseconds) that represents
2958 * a sort of fuzz factor around delta, so that we're
2959 * really telling the scheduler to wake us up any time
2960 * between now + delta - sigma and now + delta + sigma.
2961 *
2962 * The sigma parameter helps the scheduler to run more efficiently.
2963 * Sigma should be no larger than TV_WITHIN_SIGMA_MAX_USEC
2964 */
2965static inline unsigned int
2966compute_wakeup_sigma(const struct timeval *delta)
2967{
2968 ASSERT(delta->tv_sec >= 0);
2969 ASSERT(delta->tv_usec >= 0);
2970 if (delta->tv_sec < 1)
2971 {
2972 /* if < 1 sec, fuzz = # of microseconds / 8 */
2973 return (unsigned int)(delta->tv_usec >> 3);
2974 }
2975 else
2976 {
2977 /* if < 10 minutes, fuzz = 13.1% of timeout */
2978 if (delta->tv_sec < 600)
2979 {
2980 return (unsigned int)(delta->tv_sec << 17);
2981 }
2982 else
2983 {
2984 return 120 * 1000000; /* if >= 10 minutes, fuzz = 2 minutes */
2985 }
2986 }
2987}
2988
2989static void
2991{
2992 /* calculate an absolute wakeup time */
2993 ASSERT(!openvpn_gettimeofday(&mi->wakeup, NULL));
2994 tv_add(&mi->wakeup, &mi->context.c2.timeval);
2995
2996 /* tell scheduler to wake us up at some point in the future */
2997 schedule_add_entry(m->schedule, (struct schedule_entry *)mi, &mi->wakeup,
2999}
3000
3001#if defined(ENABLE_ASYNC_PUSH)
3002static void
3003add_inotify_file_watch(struct multi_context *m, struct multi_instance *mi, int inotify_fd,
3004 const char *file)
3005{
3006 /* watch acf file */
3007 int watch_descriptor = inotify_add_watch(inotify_fd, file, IN_CLOSE_WRITE | IN_ONESHOT);
3008 if (watch_descriptor >= 0)
3009 {
3010 if (mi->inotify_watch != -1)
3011 {
3012 hash_remove(m->inotify_watchers, (void *)(uintptr_t)mi->inotify_watch);
3013 }
3014 hash_add(m->inotify_watchers, (void *)(uintptr_t)watch_descriptor, mi, true);
3015 mi->inotify_watch = watch_descriptor;
3016 }
3017 else
3018 {
3019 msg(M_NONFATAL | M_ERRNO, "MULTI: inotify_add_watch error");
3020 }
3021}
3022#endif /* if defined(ENABLE_ASYNC_PUSH) */
3023
3024/*
3025 * Figure instance-specific timers, convert
3026 * earliest to absolute time in mi->wakeup,
3027 * call scheduler with our future wakeup time.
3028 *
3029 * Also close context on signal.
3030 */
3031bool
3032multi_process_post(struct multi_context *m, struct multi_instance *mi, const unsigned int flags)
3033{
3034 bool ret = true;
3035
3036 if (!IS_SIG(&mi->context)
3037 && ((flags & MPP_PRE_SELECT)))
3038 {
3039#if defined(ENABLE_ASYNC_PUSH)
3040 bool was_unauthenticated = true;
3041 const struct key_state *ks = NULL;
3042 if (mi->context.c2.tls_multi)
3043 {
3045 was_unauthenticated = (ks->authenticated == KS_AUTH_FALSE);
3046 }
3047#endif
3048
3049 /* figure timeouts and fetch possible outgoing
3050 * to_link packets (such as ping or TLS control) */
3051 pre_select(&mi->context);
3052
3053#if defined(ENABLE_ASYNC_PUSH)
3054 /*
3055 * if we see the state transition from unauthenticated to deferred
3056 * and an auth_control_file, we assume it got just added and add
3057 * inotify watch to that file
3058 */
3059 if (ks && ks->plugin_auth.auth_control_file && was_unauthenticated
3060 && (ks->authenticated == KS_AUTH_DEFERRED))
3061 {
3062 add_inotify_file_watch(m, mi, m->top.c2.inotify_fd, ks->plugin_auth.auth_control_file);
3063 }
3064 if (ks && ks->script_auth.auth_control_file && was_unauthenticated
3065 && (ks->authenticated == KS_AUTH_DEFERRED))
3066 {
3067 add_inotify_file_watch(m, mi, m->top.c2.inotify_fd, ks->script_auth.auth_control_file);
3068 }
3069#endif
3070
3071 if (!IS_SIG(&mi->context))
3072 {
3073 /* connection is "established" when SSL/TLS key negotiation succeeds
3074 * and (if specified) auth user/pass succeeds */
3075
3077 {
3079 }
3080#if defined(ENABLE_ASYNC_PUSH)
3083 {
3084 add_inotify_file_watch(m, mi, m->top.c2.inotify_fd,
3086 }
3087#endif
3088 /* tell scheduler to wake us up at some point in the future */
3090 }
3091 }
3092
3093 if (IS_SIG(&mi->context))
3094 {
3095 if (flags & MPP_CLOSE_ON_SIGNAL)
3096 {
3098 ret = false;
3099 }
3100 }
3101 else
3102 {
3103 /* continue to pend on output? */
3104 multi_set_pending(m, ANY_OUT(&mi->context) ? mi : NULL);
3105
3106#ifdef MULTI_DEBUG_EVENT_LOOP
3107 printf("POST %s[%d] to=%d lo=%d/%d w=%" PRIi64 "/%ld\n", id(mi), (int)(mi == m->pending),
3109 mi->context.c2.fragment ? mi->context.c2.fragment->outgoing.len : -1,
3110 (int64_t)mi->context.c2.timeval.tv_sec, (long)mi->context.c2.timeval.tv_usec);
3111#endif
3112 }
3113
3114 if ((flags & MPP_RECORD_TOUCH) && m->mpp_touched)
3115 {
3116 *m->mpp_touched = mi;
3117 }
3118
3119 return ret;
3120}
3121
3132static bool
3134{
3135 struct hash *hash = m->hash;
3136 const uint64_t hv = hash_value(hash, real);
3137 struct hash_bucket *bucket = hash_bucket(hash, hv);
3138
3139 /* make sure that we don't assign the client to an address taken by
3140 * another client */
3141 struct hash_element *he = hash_lookup_fast(hash, bucket, real, hv);
3142 if (!he)
3143 {
3144 /* Address is not taken, everything is fine. */
3145 return true;
3146 }
3147
3148 struct multi_instance *ex_mi = he->value;
3149
3150 const struct tls_multi *m1 = mi->context.c2.tls_multi;
3151 const struct tls_multi *m2 = ex_mi->context.c2.tls_multi;
3152
3153 struct gc_arena gc = gc_new();
3154 int ret = false;
3155
3156 /* do not allow if target address is taken by client with another cert */
3158 {
3159 msg(D_MULTI_LOW, "Disallow float/connect to an address taken by another client %s",
3160 multi_instance_string(ex_mi, false, &gc));
3161
3162 mi->context.c2.buf.len = 0;
3163 goto done;
3164 }
3165
3166 /* do not allow if target address has a different username */
3167 if (m1->locked_username || m2->locked_username)
3168 {
3169 if (!m1->locked_username || !m2->locked_username
3170 || strcmp(m1->locked_username, m2->locked_username) != 0)
3171 {
3172 msg(D_MULTI_LOW, "Disallow float/connect to an address taken by another client %s",
3173 multi_instance_string(ex_mi, false, &gc));
3174 goto done;
3175 }
3176 }
3177
3178 /* It doesn't make sense to let a peer float to the address it already
3179 * has, so we disallow it. This can happen if a DCO netlink notification
3180 * gets lost and we miss a floating step.
3181 */
3182 if (m1->rx_peer_id == m2->rx_peer_id)
3183 {
3184 msg(M_WARN,
3185 "disallowing peer %" PRIu32 " (%s) from floating to "
3186 "its own address (%s)",
3188 mroute_addr_print(&mi->real, &gc));
3189 goto done;
3190 }
3191
3193 "closing instance %s due to float collision with %s "
3194 "using the same certificate and username",
3195 multi_instance_string(ex_mi, false, &gc), multi_instance_string(mi, false, &gc));
3196 multi_close_instance(m, ex_mi, false);
3197 ret = true;
3198
3199done:
3200 gc_free(&gc);
3201 return ret;
3202}
3203
3212static void
3214{
3215 struct mroute_addr real = { 0 };
3216
3217 if (mi->real.type & MR_WITH_PROTO)
3218 {
3219 real.type |= MR_WITH_PROTO;
3220 real.proto = sock->info.proto;
3221 }
3222
3223 if (!mroute_extract_openvpn_sockaddr(&real, &m->top.c2.from.dest, true))
3224 {
3225 return;
3226 }
3227
3228 if (!multi_check_dest_addr_allowed(m, mi, &real))
3229 {
3230 return;
3231 }
3232
3233 struct gc_arena gc = gc_new();
3234
3235 msg(D_MULTI_MEDIUM, "peer %" PRIu32 " (%s) floated from %s to %s",
3237 tls_common_name(mi->context.c2.tls_multi, false),
3240
3241 /* remove old address from hash table before changing address */
3242 ASSERT(hash_remove(m->hash, &mi->real));
3243
3244 /* change external network address of the remote peer */
3245 mi->real = real;
3246 generate_prefix(mi);
3247
3248 mi->context.c2.from = m->top.c2.from;
3249 mi->context.c2.to_link_addr = &mi->context.c2.from;
3250
3251 /* inherit parent link_socket and link_socket_info */
3252 mi->context.c2.link_sockets[0] = sock;
3254
3256
3257 ASSERT(hash_add(m->hash, &mi->real, mi, false));
3258
3259#ifdef ENABLE_MANAGEMENT
3260 ASSERT(hash_add(m->cid_hash, &mi->context.c2.mda_context.cid, mi, true));
3261#endif
3262
3263 gc_free(&gc);
3264}
3265
3266/*
3267 * Called when an instance should be closed due to the
3268 * reception of a soft signal.
3269 */
3270void
3272{
3273 remap_signal(&mi->context);
3274 set_prefix(mi);
3275 print_signal(mi->context.sig, "client-instance", D_MULTI_LOW);
3276 clear_prefix();
3277 multi_close_instance(m, mi, false);
3278}
3279
3280#if (defined(ENABLE_DCO) && (defined(TARGET_LINUX) || defined(TARGET_FREEBSD))) \
3281 || defined(ENABLE_MANAGEMENT)
3282static void
3283multi_signal_instance(struct multi_context *m, struct multi_instance *mi, const int sig)
3284{
3285 mi->context.sig->signal_received = sig;
3287}
3288#endif
3289
3290#if defined(ENABLE_DCO)
3291static void
3292process_incoming_del_peer(struct multi_context *m, struct multi_instance *mi, dco_context_t *dco)
3293{
3294 const char *reason = "ovpn-dco: unknown reason";
3295 switch (dco->dco_del_peer_reason)
3296 {
3298 reason = "ovpn-dco: ping expired";
3299 break;
3300
3302 reason = "ovpn-dco: transport error";
3303 break;
3304
3306 reason = "ovpn-dco: transport disconnected";
3307 break;
3308
3310 /* We assume that is ourselves. Unfortunately, sometimes these
3311 * events happen with enough delay that they can have an order of
3312 *
3313 * dco_del_peer x
3314 * [new client connecting]
3315 * dco_new_peer x
3316 * event from dco_del_peer arrives.
3317 *
3318 * if we do not ignore this we get desynced with the kernel
3319 * since we assume the peer-id is free again. The other way would
3320 * be to send a dco_del_peer again
3321 */
3322 return;
3323 }
3324
3325 /* When kernel already deleted the peer, the socket is no longer
3326 * installed, and we do not need to clean up the state in the kernel */
3327 mi->context.c2.tls_multi->dco_peer_id = -1;
3328 mi->context.sig->signal_text = reason;
3330}
3331
3332void
3334{
3335 ASSERT(dco->c->multi);
3336
3337 struct multi_context *m = dco->c->multi;
3338
3339 int peer_id = dco->dco_message_peer_id;
3340
3341 /* no peer-specific message delivered -> nothing to process.
3342 * bail out right away
3343 */
3344 if (peer_id < 0)
3345 {
3346 return;
3347 }
3348
3349 if (((uint32_t)peer_id < m->max_clients) && m->instances[peer_id])
3350 {
3351 struct multi_instance *mi = m->instances[peer_id];
3352 set_prefix(mi);
3353 if (dco->dco_message_type == OVPN_CMD_DEL_PEER)
3354 {
3355 process_incoming_del_peer(m, mi, dco);
3356 }
3357 else if (dco->dco_message_type == OVPN_CMD_FLOAT_PEER)
3358 {
3359 ASSERT(mi->context.c2.link_sockets[0]);
3361 &m->top.c2.from.dest,
3362 (struct sockaddr *)&dco->dco_float_peer_ss);
3364 CLEAR(dco->dco_float_peer_ss);
3365 }
3366 else if (dco->dco_message_type == OVPN_CMD_SWAP_KEYS)
3367 {
3369 }
3370 clear_prefix();
3371 }
3372 else
3373 {
3374 msglvl_t msglevel = D_DCO;
3375 if (dco->dco_message_type == OVPN_CMD_DEL_PEER
3376 && dco->dco_del_peer_reason == OVPN_DEL_PEER_REASON_USERSPACE)
3377 {
3378 /* we receive OVPN_CMD_DEL_PEER message with reason USERSPACE
3379 * after we kill the peer ourselves. This peer may have already
3380 * been deleted, so we end up here.
3381 * In this case, print the following debug message with DCO_DEBUG
3382 * level only to avoid polluting the standard DCO level with this
3383 * harmless event.
3384 */
3385 msglevel = D_DCO_DEBUG;
3386 }
3387 msg(msglevel,
3388 "Received DCO message for unknown peer-id: %d, "
3389 "type %d, del_peer_reason %d",
3390 peer_id, dco->dco_message_type, dco->dco_del_peer_reason);
3391 }
3392}
3393#endif /* if defined(ENABLE_DCO) */
3394
3401static void
3402multi_process_incoming_link_data(struct multi_context *m, bool floated, struct link_socket *sock)
3403{
3404 struct link_socket_info *lsi = &sock->info;
3405 const uint8_t *orig_buf;
3406
3407 /* decrypt in instance context */
3408 struct context *c = &m->pending->context;
3409
3410 orig_buf = c->c2.buf.data;
3411 if (process_incoming_link_part1(c, lsi, floated))
3412 {
3413 /* nonzero length means that we have a valid, decrypted packed */
3414 if (floated && c->c2.buf.len > 0)
3415 {
3416 multi_process_float(m, m->pending, sock);
3417 }
3418
3419 process_incoming_link_part2(c, lsi, orig_buf);
3420 }
3421
3423 {
3424 struct mroute_addr src, dest;
3425 /* extract packet source and dest addresses */
3426 unsigned int mroute_flags =
3428
3429 /* drop packet if extract failed */
3430 if (!(mroute_flags & MROUTE_EXTRACT_SUCCEEDED))
3431 {
3432 c->c2.to_tun.len = 0;
3433 }
3434 /* make sure that source address is associated with this client */
3435 else if (multi_get_instance_by_virtual_addr(m, &src, true) != m->pending)
3436 {
3437 /* IPv6 link-local address (fe80::xxx)? */
3438 if ((src.type & MR_ADDR_MASK) == MR_ADDR_IPV6
3439 && IN6_IS_ADDR_LINKLOCAL(&src.v6.addr))
3440 {
3441 /* do nothing, for now. TODO: add address learning */
3442 }
3443 else
3444 {
3445 struct gc_arena gc = gc_new();
3447 "MULTI: bad source address from client [%s], packet dropped",
3448 mroute_addr_print(&src, &gc));
3449 gc_free(&gc);
3450 }
3451 c->c2.to_tun.len = 0;
3452 }
3453 /* client-to-client communication enabled? */
3454 else if (m->enable_c2c)
3455 {
3456 /* multicast? */
3457 if (mroute_flags & MROUTE_EXTRACT_MCAST)
3458 {
3459 /* for now, treat multicast as broadcast */
3460 multi_bcast(m, &c->c2.to_tun, m->pending, 0);
3461 }
3462 else /* possible client to client routing */
3463 {
3464 ASSERT(!(mroute_flags & MROUTE_EXTRACT_BCAST));
3465 struct multi_instance *mi = multi_get_instance_by_virtual_addr(m, &dest, true);
3466
3467 /* if dest addr is a known client, route to it */
3468 if (mi)
3469 {
3470 {
3471 multi_unicast(m, &c->c2.to_tun, mi);
3473 }
3474 c->c2.to_tun.len = 0;
3475 }
3476 }
3477 }
3478 }
3479 else if (TUNNEL_TYPE(m->top.c1.tuntap) == DEV_TYPE_TAP)
3480 {
3481 uint16_t vid = 0;
3482
3483 if (m->top.options.vlan_tagging)
3484 {
3485 if (vlan_is_tagged(&c->c2.to_tun))
3486 {
3487 /* Drop VLAN-tagged frame. */
3488 msg(D_VLAN_DEBUG, "dropping incoming VLAN-tagged frame");
3489 c->c2.to_tun.len = 0;
3490 }
3491 else
3492 {
3493 vid = c->options.vlan_pvid;
3494 }
3495 }
3496 /* extract packet source and dest addresses */
3497 struct mroute_addr src, dest;
3498 /* extract packet source and dest addresses */
3499 unsigned int mroute_flags =
3501
3502 if (mroute_flags & MROUTE_EXTRACT_SUCCEEDED)
3503 {
3504 if (multi_learn_addr(m, m->pending, &src, 0) == m->pending)
3505 {
3506 /* check for broadcast */
3507 if (m->enable_c2c)
3508 {
3509 if (mroute_flags & (MROUTE_EXTRACT_BCAST | MROUTE_EXTRACT_MCAST))
3510 {
3511 multi_bcast(m, &c->c2.to_tun, m->pending, vid);
3512 }
3513 else /* try client-to-client routing */
3514 {
3515 struct multi_instance *mi = multi_get_instance_by_virtual_addr(m, &dest, false);
3516
3517 /* if dest addr is a known client, route to it */
3518 if (mi)
3519 {
3520 multi_unicast(m, &c->c2.to_tun, mi);
3522 c->c2.to_tun.len = 0;
3523 }
3524 }
3525 }
3526 }
3527 else
3528 {
3529 struct gc_arena gc = gc_new();
3531 "MULTI: bad source address from client [%s], packet dropped",
3532 mroute_addr_print(&src, &gc));
3533 c->c2.to_tun.len = 0;
3534 gc_free(&gc);
3535 }
3536 }
3537 else
3538 {
3539 c->c2.to_tun.len = 0;
3540 }
3541 }
3542}
3543
3544/*
3545 * Process packets in the TCP/UDP socket -> TUN/TAP interface direction,
3546 * i.e. client -> server direction.
3547 */
3548bool
3550 const unsigned int mpp_flags, struct link_socket *sock)
3551{
3552 struct context *c;
3553 bool ret = true;
3554 bool floated = false;
3555
3556 if (m->pending)
3557 {
3558 return true;
3559 }
3560
3561 if (!instance)
3562 {
3563#ifdef MULTI_DEBUG_EVENT_LOOP
3564 printf("TCP/UDP -> TUN [%d]\n", BLEN(&m->top.c2.buf));
3565#endif
3566 multi_set_pending(m, multi_get_create_instance_udp(m, &floated, sock));
3567 }
3568 else
3569 {
3570 multi_set_pending(m, instance);
3571 }
3572
3573 if (!m->pending)
3574 {
3575 return true;
3576 }
3577 set_prefix(m->pending);
3578
3579 /* get instance context */
3580 c = &m->pending->context;
3581
3582 if (!instance)
3583 {
3584 /* transfer packet pointer from top-level context buffer to instance */
3585 c->c2.buf = m->top.c2.buf;
3586
3587 /* transfer from-addr from top-level context buffer to instance */
3588 if (!floated)
3589 {
3590 c->c2.from = m->top.c2.from;
3591 }
3592 }
3593
3594 if (BLEN(&c->c2.buf) > 0)
3595 {
3596 multi_process_incoming_link_data(m, floated, sock);
3597 }
3598
3599 /* postprocess and set wakeup */
3600 ret = multi_process_post(m, m->pending, mpp_flags);
3601
3602 clear_prefix();
3603
3604 return ret;
3605}
3606
3607/*
3608 * Process packets in the TUN/TAP interface -> TCP/UDP socket direction,
3609 * i.e. server -> client direction.
3610 */
3611bool
3612multi_process_incoming_tun(struct multi_context *m, const unsigned int mpp_flags)
3613{
3614 bool ret = true;
3615
3616 if (BLEN(&m->top.c2.buf) > 0)
3617 {
3618 unsigned int mroute_flags;
3619 struct mroute_addr src = { 0 }, dest = { 0 };
3620 const int dev_type = TUNNEL_TYPE(m->top.c1.tuntap);
3621 int16_t vid = 0;
3622
3623#ifdef MULTI_DEBUG_EVENT_LOOP
3624 printf("TUN -> TCP/UDP [%d]\n", BLEN(&m->top.c2.buf));
3625#endif
3626
3627 if (m->pending)
3628 {
3629 return true;
3630 }
3631
3632 if (dev_type == DEV_TYPE_TAP && m->top.options.vlan_tagging)
3633 {
3634 vid = vlan_decapsulate(&m->top, &m->top.c2.buf);
3635 if (vid < 0)
3636 {
3637 return false;
3638 }
3639 }
3640
3641 /*
3642 * Route an incoming tun/tap packet to
3643 * the appropriate multi_instance object.
3644 */
3645 mroute_flags = mroute_extract_addr_from_packet(&src, &dest, vid, &m->top.c2.buf, dev_type);
3646
3647 if (mroute_flags & MROUTE_EXTRACT_SUCCEEDED)
3648 {
3649 struct context *c;
3650
3651 /* broadcast or multicast dest addr? */
3652 if (mroute_flags & (MROUTE_EXTRACT_BCAST | MROUTE_EXTRACT_MCAST))
3653 {
3654 /* for now, treat multicast as broadcast */
3655 multi_bcast(m, &m->top.c2.buf, NULL, vid);
3656 }
3657 else
3658 {
3660 m, multi_get_instance_by_virtual_addr(m, &dest, dev_type == DEV_TYPE_TUN));
3661
3662 if (m->pending)
3663 {
3664 /* get instance context */
3665 c = &m->pending->context;
3666
3667 set_prefix(m->pending);
3668
3669 {
3671 {
3672 /* transfer packet pointer from top-level context buffer to instance */
3673 c->c2.buf = m->top.c2.buf;
3674 }
3675 else
3676 {
3677 /* drop packet */
3679 "MULTI: packet dropped due to output saturation (multi_process_incoming_tun)");
3680 buf_reset_len(&c->c2.buf);
3681 }
3682 }
3683
3684 /* encrypt in instance context */
3686
3687 /* postprocess and set wakeup */
3688 ret = multi_process_post(m, m->pending, mpp_flags);
3689
3690 clear_prefix();
3691 }
3692 }
3693 }
3694 }
3695 return ret;
3696}
3697
3698/*
3699 * Process a possible client-to-client/bcast/mcast message in the
3700 * queue.
3701 */
3702struct multi_instance *
3704{
3705 struct mbuf_item item;
3706
3707 if (mbuf_extract_item(ms, &item)) /* cleartext IP packet */
3708 {
3709 unsigned int pip_flags = PIPV4_PASSTOS | PIPV6_ICMP_NOHOST_SERVER;
3710
3711 set_prefix(item.instance);
3712 item.instance->context.c2.buf = item.buffer->buf;
3713 if (item.buffer->flags
3714 & MF_UNICAST) /* --mssfix doesn't make sense for broadcast or multicast */
3715 {
3716 pip_flags |= PIP_MSSFIX;
3717 }
3718 process_ip_header(&item.instance->context, pip_flags, &item.instance->context.c2.buf,
3719 item.instance->context.c2.link_sockets[0]);
3720 encrypt_sign(&item.instance->context, true);
3721 mbuf_free_buf(item.buffer);
3722
3723 dmsg(D_MULTI_DEBUG, "MULTI: C2C/MCAST/BCAST");
3724
3725 clear_prefix();
3726 return item.instance;
3727 }
3728 else
3729 {
3730 return NULL;
3731 }
3732}
3733
3734/*
3735 * Called when an I/O wait times out. Usually means that a particular
3736 * client instance object needs timer-based service.
3737 */
3738bool
3739multi_process_timeout(struct multi_context *m, const unsigned int mpp_flags)
3740{
3741 bool ret = true;
3742
3743#ifdef MULTI_DEBUG_EVENT_LOOP
3744 printf("%s -> TIMEOUT\n", id(m->earliest_wakeup));
3745#endif
3746
3747 /* instance marked for wakeup? */
3748 if (m->earliest_wakeup)
3749 {
3751 {
3755 }
3756 else
3757 {
3759 ret = multi_process_post(m, m->earliest_wakeup, mpp_flags);
3760 clear_prefix();
3761 }
3762 m->earliest_wakeup = NULL;
3763 }
3764 return ret;
3765}
3766
3767/*
3768 * Drop a TUN/TAP outgoing packet..
3769 */
3770void
3771multi_process_drop_outgoing_tun(struct multi_context *m, const unsigned int mpp_flags)
3772{
3773 struct multi_instance *mi = m->pending;
3774
3775 ASSERT(mi);
3776
3777 set_prefix(mi);
3778
3779 msg(D_MULTI_ERRORS, "MULTI: Outgoing TUN queue full, dropped packet len=%d",
3780 mi->context.c2.to_tun.len);
3781
3782 buf_reset(&mi->context.c2.to_tun);
3783
3784 multi_process_post(m, mi, mpp_flags);
3785 clear_prefix();
3786}
3787
3788/*
3789 * Per-client route quota management
3790 */
3791
3792void
3794{
3795 struct gc_arena gc = gc_new();
3797 "MULTI ROUTE: route quota (%d) exceeded for %s (see --max-routes-per-client option)",
3799 gc_free(&gc);
3800}
3801
3802#ifdef ENABLE_DEBUG
3803/*
3804 * Flood clients with random packets
3805 */
3806static void
3807gremlin_flood_clients(struct multi_context *m)
3808{
3809 const int level = GREMLIN_PACKET_FLOOD_LEVEL(m->top.options.gremlin);
3810 if (level)
3811 {
3812 struct gc_arena gc = gc_new();
3813 struct buffer buf = alloc_buf_gc(BUF_SIZE(&m->top.c2.frame), &gc);
3814 struct packet_flood_parms parm = get_packet_flood_parms(level);
3815 int i;
3816
3817 ASSERT(buf_init(&buf, m->top.c2.frame.buf.headroom));
3818 parm.packet_size = min_int(parm.packet_size, m->top.c2.frame.buf.payload_size);
3819
3820 msg(D_GREMLIN, "GREMLIN_FLOOD_CLIENTS: flooding clients with %d packets of size %d",
3821 parm.n_packets, parm.packet_size);
3822
3823 for (i = 0; i < parm.packet_size; ++i)
3824 {
3825 ASSERT(buf_write_u8(&buf, (uint8_t)(get_random() & 0xFF)));
3826 }
3827
3828 for (i = 0; i < parm.n_packets; ++i)
3829 {
3830 multi_bcast(m, &buf, NULL, 0);
3831 }
3832
3833 gc_free(&gc);
3834 }
3835}
3836#endif /* ifdef ENABLE_DEBUG */
3837
3838static bool
3840{
3841 struct timeval null;
3842 CLEAR(null);
3844}
3845
3846/*
3847 * Process timers in the top-level context
3848 */
3849void
3851{
3852 /* possibly reap instances/routes in vhash */
3854
3855 /* possibly print to status log */
3856 if (m->top.c1.status_output)
3857 {
3859 {
3861 }
3862 }
3863
3864 /* possibly flush ifconfig-pool file */
3866
3867#ifdef ENABLE_DEBUG
3868 gremlin_flood_clients(m);
3869#endif
3870
3871 /* Should we check for stale routes? */
3873 {
3875 }
3876}
3877
3878static void
3880{
3881 inherit_context_top(&top->multi->top, top);
3883}
3884
3885static void
3891
3892static bool
3894{
3895 return (sig == SIGUSR1 || sig == SIGTERM || sig == SIGHUP || sig == SIGINT);
3896}
3897
3898static void
3900{
3901 /* tell all clients to restart */
3902 for (uint32_t i = 0; i <= m->max_peerid; i++)
3903 {
3904 struct multi_instance *mi = m->instances[i];
3905 if (mi && !mi->halt && proto_is_dgram(mi->context.c2.link_sockets[0]->info.proto))
3906 {
3907 send_control_channel_string(&mi->context, next_server ? "RESTART,[N]" : "RESTART",
3908 D_PUSH);
3910 }
3911 }
3912
3913 /* reschedule signal */
3915 struct timeval tv = { .tv_sec = 2, .tv_usec = 0 };
3917
3919
3923
3924 signal_reset(m->top.sig, 0);
3925}
3926
3927/*
3928 * Return true if event loop should break,
3929 * false if it should continue.
3930 */
3931bool
3933{
3934 if (signal_reset(m->top.sig, SIGUSR2) == SIGUSR2)
3935 {
3936 struct status_output *so = status_open(NULL, 0, M_INFO, NULL, 0);
3938 status_close(so);
3939 return false;
3940 }
3944 {
3946 return false;
3947 }
3948 return true;
3949}
3950
3951/*
3952 * Management subsystem callbacks
3953 */
3954#ifdef ENABLE_MANAGEMENT
3955
3956static void
3957management_callback_status(void *arg, const int version, struct status_output *so)
3958{
3959 struct multi_context *m = (struct multi_context *)arg;
3960
3961 if (!version)
3962 {
3964 }
3965 else
3966 {
3967 multi_print_status(m, so, version);
3968 }
3969}
3970
3971static int
3973{
3974 const struct multi_context *m = (struct multi_context *)arg;
3975 return m->n_clients;
3976}
3977
3978static int
3979management_callback_kill_by_cn(void *arg, const char *del_cn)
3980{
3981 struct multi_context *m = (struct multi_context *)arg;
3982 int count = 0;
3983
3984 for (uint32_t i = 0; i <= m->max_peerid; i++)
3985 {
3986 struct multi_instance *mi = m->instances[i];
3987 if (mi && !mi->halt)
3988 {
3989 const char *cn = tls_common_name(mi->context.c2.tls_multi, false);
3990 if (cn && !strcmp(cn, del_cn))
3991 {
3993 ++count;
3994 }
3995 }
3996 }
3997 return count;
3998}
3999
4000static int
4001management_callback_kill_by_addr(void *arg, const in_addr_t addr, const uint16_t port, const uint8_t proto)
4002{
4003 struct multi_context *m = (struct multi_context *)arg;
4004 struct openvpn_sockaddr saddr;
4005 struct mroute_addr maddr;
4006 int count = 0;
4007
4008 CLEAR(saddr);
4009 saddr.addr.in4.sin_family = AF_INET;
4010 saddr.addr.in4.sin_addr.s_addr = htonl(addr);
4011 saddr.addr.in4.sin_port = htons(port);
4012 maddr.proto = proto;
4013 if (mroute_extract_openvpn_sockaddr(&maddr, &saddr, true))
4014 {
4015 for (uint32_t i = 0; i <= m->max_peerid; i++)
4016 {
4017 struct multi_instance *mi = m->instances[i];
4018 if (mi && !mi->halt && mroute_addr_equal(&maddr, &mi->real))
4019 {
4021 ++count;
4022 }
4023 }
4024 }
4025 return count;
4026}
4027
4028static void
4030{
4031 struct multi_context *m = (struct multi_context *)arg;
4032 if (m->multi_io)
4033 {
4035 }
4036}
4037
4038struct multi_instance *
4039lookup_by_cid(struct multi_context *m, const unsigned long cid)
4040{
4041 if (m)
4042 {
4043 struct multi_instance *mi = (struct multi_instance *)hash_lookup(m->cid_hash, &cid);
4044 if (mi && !mi->halt)
4045 {
4046 return mi;
4047 }
4048 }
4049 return NULL;
4050}
4051
4052static bool
4053management_kill_by_cid(void *arg, const unsigned long cid, const char *kill_msg)
4054{
4055 struct multi_context *m = (struct multi_context *)arg;
4056 struct multi_instance *mi = lookup_by_cid(m, cid);
4057 if (mi)
4058 {
4059 send_restart(&mi->context, kill_msg); /* was: multi_signal_instance (m, mi, SIGTERM); */
4061 return true;
4062 }
4063 else
4064 {
4065 return false;
4066 }
4067}
4068
4069static struct tls_session *
4071 const unsigned int mda_key_id)
4072{
4073 if (multi->session[TM_INITIAL].key[KS_PRIMARY].mda_key_id == mda_key_id)
4074 {
4075 return &multi->session[TM_INITIAL];
4076 }
4077 else if (multi->session[TM_ACTIVE].key[KS_PRIMARY].mda_key_id == mda_key_id)
4078 {
4079 return &multi->session[TM_ACTIVE];
4080 }
4081 else
4082 {
4083 return NULL;
4084 }
4085}
4086
4087static bool
4088management_client_pending_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id,
4089 const char *extra, unsigned int timeout)
4090{
4091 struct multi_context *m = (struct multi_context *)arg;
4092 struct multi_instance *mi = lookup_by_cid(m, cid);
4093
4094 if (mi)
4095 {
4096 struct tls_multi *multi = mi->context.c2.tls_multi;
4097 struct tls_session *session = lookup_session_by_mda_key_id(multi, mda_key_id);
4098
4099 if (!session)
4100 {
4101 return false;
4102 }
4103
4104 /* sends INFO_PRE and AUTH_PENDING messages to client */
4105 bool ret = send_auth_pending_messages(multi, session, extra, timeout);
4108 return ret;
4109 }
4110 return false;
4111}
4112
4113
4114static bool
4115management_client_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id,
4116 const bool auth, const char *reason, const char *client_reason,
4117 struct buffer_list *cc_config) /* ownership transferred */
4118{
4119 struct multi_context *m = (struct multi_context *)arg;
4120 struct multi_instance *mi = lookup_by_cid(m, cid);
4121 bool cc_config_owned = true;
4122 bool ret = false;
4123
4124 if (mi)
4125 {
4126 ret = tls_authenticate_key(mi->context.c2.tls_multi, mda_key_id, auth, client_reason);
4127 if (ret)
4128 {
4129 if (auth)
4130 {
4132 {
4134 cc_config_owned = false;
4135 }
4136 }
4137 else if (reason)
4138 {
4139 msg(D_MULTI_LOW, "MULTI: connection rejected: %s, CLI:%s", reason,
4140 np(client_reason));
4141 }
4142 }
4143 }
4144 if (cc_config_owned && cc_config)
4145 {
4147 }
4148 return ret;
4149}
4150
4151static char *
4152management_get_peer_info(void *arg, const unsigned long cid)
4153{
4154 struct multi_context *m = (struct multi_context *)arg;
4155 struct multi_instance *mi = lookup_by_cid(m, cid);
4156 char *ret = NULL;
4157
4158 if (mi)
4159 {
4160 ret = mi->context.c2.tls_multi->peer_info;
4161 }
4162
4163 return ret;
4164}
4165
4166#endif /* ifdef ENABLE_MANAGEMENT */
4167
4168
4169void
4195
4196void
4198{
4199 /* max_clients must be less then max peer-id value */
4201
4202 for (uint32_t i = 0; i < m->max_clients; ++i)
4203 {
4204 if (!m->instances[i])
4205 {
4206 mi->context.c2.tls_multi->rx_peer_id = i;
4207 m->instances[i] = mi;
4208 break;
4209 }
4210 }
4211
4212 /* should not really end up here, since multi_create_instance returns null
4213 * if amount of clients exceeds max_clients and this method would then
4214 * also not have been called */
4216
4218 {
4220 }
4221}
4222
4233static void
4234multi_get_timeout(struct multi_context *multi, struct timeval *timeval)
4235{
4236 multi_get_timeout_instance(multi, timeval);
4237
4238#ifdef ENABLE_MANAGEMENT
4239 if (management)
4240 {
4241 management_check_bytecount_server(multi, timeval);
4242 }
4243#endif /* ENABLE_MANAGEMENT */
4244}
4245
4246/**************************************************************************/
4253static void
4255{
4256 while (true)
4257 {
4258 /* wait on tun/socket list */
4259 multi_get_timeout(multi, &multi->top.c2.timeval);
4260 const int status = multi_io_wait(multi);
4261 MULTI_CHECK_SIG(multi);
4262
4263 /* check on status of coarse timers */
4265
4266 /* timeout? */
4267 if (status > 0)
4268 {
4269 /* process the I/O which triggered select */
4270 multi_io_process_io(multi);
4271 }
4272 else if (status == 0)
4273 {
4274 multi_io_action(multi, NULL, TA_TIMEOUT, false);
4275 }
4276
4277 MULTI_CHECK_SIG(multi);
4278 }
4279}
4280
4281/*
4282 * Top level event loop.
4283 */
4284void
4286{
4287 ASSERT(top->options.mode == MODE_SERVER);
4288
4289 struct multi_context multi;
4290
4291 top->mode = CM_TOP;
4292 // cppcheck-suppress autoVariables ; yes, we know this is dangerous
4293 top->multi = &multi;
4295
4296 /* initialize top-tunnel instance */
4298 if (IS_SIG(top))
4299 {
4300 return;
4301 }
4302
4303 /* initialize global multi_context object */
4304 multi_init(top);
4305
4306 /* initialize our cloned top object */
4308
4309 /* initialize management interface */
4311
4312 /* finished with initialization */
4313 initialization_sequence_completed(top, ISC_SERVER); /* --mode server --proto tcp-server */
4314
4315#ifdef ENABLE_ASYNC_PUSH
4316 multi.top.c2.inotify_fd = inotify_init();
4317 if (multi.top.c2.inotify_fd < 0)
4318 {
4319 msg(D_MULTI_ERRORS | M_ERRNO, "MULTI: inotify_init error");
4320 }
4321#endif
4322
4323 tunnel_server_loop(&multi);
4324
4325#ifdef ENABLE_ASYNC_PUSH
4326 msg(D_LOW, "%s: close multi.top.c2.inotify_fd (%d)",
4327 __func__, multi.top.c2.inotify_fd);
4328 close(multi.top.c2.inotify_fd);
4329#endif
4330
4331 /* shut down management interface */
4333
4334 /* save ifconfig-pool */
4335 multi_ifconfig_pool_persist(&multi, true);
4336
4337 /* tear down tunnel instance (unless --persist-tun) */
4338 multi_uninit(&multi);
4339 multi_top_free(&multi);
4341}
4342
4343/* Searches for the address and deletes it if it is owned by the multi_instance */
4344static void
4345multi_unlearn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr)
4346{
4347 struct hash_element *he;
4348 const uint64_t hv = hash_value(m->vhash, addr);
4349 struct hash_bucket *bucket = hash_bucket(m->vhash, hv);
4350 struct multi_route *r = NULL;
4351
4352 /* if route currently exists, get the instance which owns it */
4353 he = hash_lookup_fast(m->vhash, bucket, addr, hv);
4354 if (he)
4355 {
4356 r = (struct multi_route *)he->value;
4357 }
4358
4359 /* if the route does not exist or exists but is not owned by the current instance, return */
4360 if (!r || r->instance != mi)
4361 {
4362 return;
4363 }
4364
4365 struct gc_arena gc = gc_new();
4366 msg(D_MULTI_LOW, "MULTI: Unlearn: %s -> %s", mroute_addr_print(&r->addr, &gc), multi_instance_string(mi, false, &gc));
4367 learn_address_script(m, NULL, "delete", &r->addr);
4369 multi_route_del(r);
4370
4371 gc_free(&gc);
4372}
4373
4379static void
4381{
4382 struct mroute_addr addr;
4383 CLEAR(addr);
4384
4385 addr.type = MR_ADDR_IPV4;
4386 addr.len = 4;
4387 addr.v4.addr = a;
4388
4389 multi_unlearn_addr(m, mi, &addr);
4390}
4391
4397static void
4398multi_unlearn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6)
4399{
4400 struct mroute_addr addr;
4401 CLEAR(addr);
4402
4403 addr.type = MR_ADDR_IPV6;
4404 addr.len = 16;
4405 addr.v6.addr = a6;
4406
4407 multi_unlearn_addr(m, mi, &addr);
4408}
4409
4410/* Function to unlearn previous ifconfig of a client in the server multi_context after a PUSH_UPDATE */
4411void
4413{
4414 in_addr_t old_addr = 0;
4415 old_addr = htonl(mi->context.c2.push_ifconfig_local);
4416 multi_unlearn_in_addr_t(m, mi, old_addr);
4417 mi->context.c2.push_ifconfig_defined = false;
4419 mi->reporting_addr = 0;
4420}
4421
4422/* Function to unlearn previous ifconfig-ipv6 of a client in the server multi_context after a PUSH_UPDATE */
4423void
4425{
4426 struct in6_addr old_addr6;
4427 CLEAR(old_addr6);
4428 old_addr6 = mi->context.c2.push_ifconfig_ipv6_local;
4429 multi_unlearn_in6_addr(m, mi, old_addr6);
4433}
4434
4445void
4446update_vhash(struct multi_context *m, struct multi_instance *mi, const char *new_ip, const char *new_ipv6)
4447{
4448 if (new_ip)
4449 {
4450 /* Remove old IP */
4452 {
4453 unlearn_ifconfig(m, mi);
4454 }
4455
4456 /* Add new IP */
4457 struct in_addr new_addr;
4458 CLEAR(new_addr);
4459 if (inet_pton(AF_INET, new_ip, &new_addr) == 1
4460 && multi_learn_in_addr_t(m, mi, ntohl(new_addr.s_addr), -1, true))
4461 {
4462 mi->context.c2.push_ifconfig_defined = true;
4463 mi->context.c2.push_ifconfig_local = ntohl(new_addr.s_addr);
4464 /* set our client's VPN endpoint for status reporting purposes */
4466 }
4467 }
4468
4469 if (new_ipv6)
4470 {
4471 /* Remove old IPv6 */
4473 {
4474 unlearn_ifconfig_ipv6(m, mi);
4475 }
4476
4477 /* Add new IPv6 */
4478 struct in6_addr new_addr6;
4479 CLEAR(new_addr6);
4480 if (inet_pton(AF_INET6, new_ipv6, &new_addr6) == 1
4481 && multi_learn_in6_addr(m, mi, new_addr6, -1, true))
4482 {
4484 mi->context.c2.push_ifconfig_ipv6_local = new_addr6;
4485 /* set our client's VPN endpoint for status reporting purposes */
4487 }
4488 }
4489}
4490
4491bool
4493{
4494 in_addr_t local_addr, local_netmask;
4495
4497 {
4498 /* If we do not have a local address, we just return false as
4499 * this check doesn't make sense. */
4500 return false;
4501 }
4502
4503 /* if it falls into the network defined by ifconfig_local we assume
4504 * it is already known to DCO and only install "extra" iroutes */
4505 inet_pton(AF_INET, o->ifconfig_local, &local_addr);
4506 inet_pton(AF_INET, o->ifconfig_remote_netmask, &local_netmask);
4507
4508 return (local_addr & local_netmask) != (dest & local_netmask);
4509}
4510
4511bool
4512multi_check_push_ifconfig_ipv6_extra_route(const struct options *o, const struct in6_addr *dest)
4513{
4515 {
4516 /* If we do not have a local address, we just return false as
4517 * this check doesn't make sense. */
4518 return false;
4519 }
4520
4521 /* if it falls into the network defined by ifconfig_local we assume
4522 * it is already known to DCO and only install "extra" iroutes */
4523 struct in6_addr ifconfig_local;
4524 if (inet_pton(AF_INET6, o->ifconfig_ipv6_local, &ifconfig_local) != 1)
4525 {
4526 return false;
4527 }
4528
4529 return (!ipv6_net_contains_host(&ifconfig_local, o->ifconfig_ipv6_netbits,
4530 dest));
4531}
void argv_parse_cmd(struct argv *argres, const char *cmdstr)
Parses a command string, tokenizes it and puts each element into a separate struct argv argument slot...
Definition argv.c:481
void argv_free(struct argv *a)
Frees all memory allocations allocated by the struct argv related functions.
Definition argv.c:101
bool argv_printf(struct argv *argres, const char *format,...)
printf() variant which populates a struct argv.
Definition argv.c:438
bool argv_printf_cat(struct argv *argres, const char *format,...)
printf() inspired argv concatenation.
Definition argv.c:462
struct argv argv_new(void)
Allocates a new struct argv and ensures it is initialised.
Definition argv.c:87
void generate_auth_token(const struct user_pass *up, struct tls_multi *multi)
Generate an auth token based on username and timestamp.
Definition auth_token.c:179
bool buf_printf(struct buffer *buf, const char *format,...)
printf-style append to a buffer with overflow check.
Definition buffer.c:226
void buffer_list_free(struct buffer_list *ol)
Frees a buffer list and all the buffers in it.
Definition buffer.c:1155
struct buffer alloc_buf_gc(size_t size, struct gc_arena *gc)
Allocate a buffer of the given size under garbage collection.
Definition buffer.c:77
char * string_alloc(const char *str, struct gc_arena *gc)
Duplicate a string, allocating memory under garbage collection.
Definition buffer.c:606
#define ALLOC_OBJ(dptr, type)
Allocate memory for a single object of the given type.
Definition buffer.h:2027
#define BSTR(buf)
Return the buffer content pointer cast to char *.
Definition buffer.h:157
static void buf_reset(struct buffer *buf)
Reset a buffer to an undefined (unallocated) state.
Definition buffer.h:599
static bool buf_write_u8(struct buffer *dest, uint8_t data)
Append a uint8_t to a buffer.
Definition buffer.h:1306
#define BLEN(buf)
Return the length of the buffer content in bytes.
Definition buffer.h:151
static void buf_reset_len(struct buffer *buf)
Reset the length and offset of a buffer to zero.
Definition buffer.h:616
static void strncpynt(char *dest, const char *src, size_t maxlen)
Like strncpy() but always null-terminates the destination.
Definition buffer.h:710
static void gc_free(struct gc_arena *a)
Free all allocations in a garbage collection arena.
Definition buffer.h:1976
#define ALLOC_OBJ_CLEAR(dptr, type)
Allocate and zero-initialise memory for a single object of the given type.
Definition buffer.h:2038
#define buf_init(buf, offset)
Definition buffer.h:364
static struct gc_arena gc_new(void)
Allocate and return a new, empty garbage collection arena.
Definition buffer.h:1960
#define CCD_DEFAULT
Definition common.h:63
#define counter_format
Definition common.h:32
bool check_compression_settings_valid(struct compress_options *info, msglvl_t msglevel)
Checks if the compression settings are valid.
Definition comp.c:162
#define COMP_ALG_STUB
support compression command byte and framing without actual compression
Definition comp.h:56
#define COMP_F_MIGRATE
push stub-v2 or comp-lzo no when we see a client with comp-lzo in occ
Definition comp.h:47
const char * translate_cipher_name_to_openvpn(const char *cipher_name)
Translate a crypto library cipher name to an OpenVPN cipher name.
Definition crypto.c:1806
int64_t get_random(void)
an analogue to the random() function, but use prng_bytes and also int64_t instead of long to avoid LL...
Definition crypto.c:1735
#define CO_USE_TLS_KEY_MATERIAL_EXPORT
Bit-flag indicating that data channel key derivation is done using TLS keying material export [RFC570...
Definition crypto.h:359
#define CO_USE_DYNAMIC_TLS_CRYPT
Bit-flag indicating that renegotiations are using tls-crypt with a TLS-EKM derived key.
Definition crypto.h:375
#define CO_EPOCH_DATA_KEY_FORMAT
Bit-flag indicating the epoch the data format.
Definition crypto.h:379
#define CO_USE_CC_EXIT_NOTIFY
Bit-flag indicating that explicit exit notifies should be sent via the control channel instead of usi...
Definition crypto.h:371
Data Channel Cryptography SSL library-specific backend interface.
bool cipher_kt_mode_aead(const char *ciphername)
Check if the supplied cipher is a supported AEAD mode cipher.
static int dco_get_peer_stats_multi(dco_context_t *dco, const bool raise_sigusr1_on_err)
Definition dco.h:369
static void dco_delete_iroutes(openvpn_net_ctx_t *net_ctx, const struct context *c)
Definition dco.h:364
static void dco_install_iroute(struct multi_context *m, struct multi_instance *mi, struct mroute_addr *addr)
Definition dco.h:359
static bool dco_check_option(msglvl_t msglevel, const struct options *o)
Definition dco.h:274
void * dco_context_t
Definition dco.h:259
static int dco_multi_add_new_peer(struct multi_context *m, struct multi_instance *mi)
Definition dco.h:353
void setenv_counter(struct env_set *es, const char *name, counter_type value)
Definition env_set.c:281
void setenv_int(struct env_set *es, const char *name, int value)
Definition env_set.c:289
void setenv_str(struct env_set *es, const char *name, const char *value)
Definition env_set.c:305
struct env_set * env_set_create(struct gc_arena *gc)
Definition env_set.c:155
void setenv_long_long(struct env_set *es, const char *name, long long value)
Definition env_set.c:297
void setenv_del(struct env_set *es, const char *name)
Definition env_set.c:350
#define D_PUSH
Definition errlevel.h:82
#define D_MULTI_ERRORS
Definition errlevel.h:64
#define D_VLAN_DEBUG
Definition errlevel.h:153
#define D_IMPORT_ERRORS
Definition errlevel.h:63
#define D_ROUTE_QUOTA
Definition errlevel.h:89
#define D_MULTI_MEDIUM
Definition errlevel.h:101
#define D_DCO
Definition errlevel.h:93
#define D_MULTI_DEBUG
Definition errlevel.h:126
#define D_MULTI_DROPPED
Definition errlevel.h:100
#define D_DCO_DEBUG
Definition errlevel.h:117
#define D_MULTI_LOW
Definition errlevel.h:85
#define D_TLS_ERRORS
Definition errlevel.h:58
#define D_LOW
Definition errlevel.h:96
#define M_INFO
Definition errlevel.h:54
#define D_GREMLIN
Definition errlevel.h:77
const struct rw_handle * event_t
Definition event.h:89
@ EVENT_ARG_MULTI_INSTANCE
Definition event.h:134
void reschedule_multi_process(struct context *c)
Reschedule tls_multi_process.
Definition forward.c:397
bool send_control_channel_string(struct context *c, const char *str, msglvl_t msglevel)
Definition forward.c:404
void pre_select(struct context *c)
Definition forward.c:1988
void process_ip_header(struct context *c, unsigned int flags, struct buffer *buf, struct link_socket *sock)
Definition forward.c:1685
void extract_dco_float_peer_addr(const sa_family_t socket_family, struct openvpn_sockaddr *out_osaddr, const struct sockaddr *float_sa)
Transfers float_sa data extracted from an incoming DCO PEER_FLOAT_NTF to out_osaddr for later process...
Definition forward.c:1234
Interface functions to the internal and external multiplexers.
#define PIP_MSSFIX
Definition forward.h:337
static void register_activity(struct context *c, const int64_t size)
Definition forward.h:364
#define PIPV6_ICMP_NOHOST_SERVER
Definition forward.h:342
static struct link_socket_info * get_link_socket_info(struct context *c)
Definition forward.h:351
#define ANY_OUT(c)
Definition forward.h:39
#define PIPV4_PASSTOS
Definition forward.h:336
#define TM_INITIAL
As yet un-trusted tls_session \ being negotiated.
Definition ssl_common.h:545
#define KS_PRIMARY
Primary key state index.
Definition ssl_common.h:464
#define TM_ACTIVE
Active tls_session.
Definition ssl_common.h:544
void encrypt_sign(struct context *c, bool comp_frag)
Process a data channel packet that will be sent through a VPN tunnel.
Definition forward.c:644
void tunnel_server(struct context *top)
Main event loop for OpenVPN in server mode.
Definition multi.c:4285
static void tunnel_server_loop(struct multi_context *multi)
Main event loop for OpenVPN in point-to-multipoint server mode.
Definition multi.c:4254
bool process_incoming_link_part1(struct context *c, struct link_socket_info *lsi, bool floated)
Starts processing a packet read from the external network interface.
Definition forward.c:1008
void process_incoming_link_part2(struct context *c, struct link_socket_info *lsi, const uint8_t *orig_buf)
Continues processing a packet read from the external network interface.
Definition forward.c:1141
bool multi_process_incoming_link(struct multi_context *m, struct multi_instance *instance, const unsigned int mpp_flags, struct link_socket *sock)
Demultiplex and process a packet received over the external network interface.
Definition multi.c:3549
struct multi_instance * multi_get_create_instance_udp(struct multi_context *m, bool *floated, struct link_socket *sock)
Get, and if necessary create, the multi_instance associated with a packet's source address.
Definition mudp.c:403
void process_incoming_tun(struct context *c, struct link_socket *out_sock)
Process a packet read from the virtual tun/tap network interface.
Definition forward.c:1500
bool multi_process_incoming_tun(struct multi_context *m, const unsigned int mpp_flags)
Determine the destination VPN tunnel of a packet received over the virtual tun/tap network interface ...
Definition multi.c:3612
void uninit_management_callback(void)
Definition init.c:4398
void initialization_sequence_completed(struct context *c, const unsigned int flags)
Definition init.c:1514
void close_instance(struct context *c)
Definition init.c:4732
void inherit_context_top(struct context *dest, const struct context *src)
Definition init.c:4893
void free_context_buffers(struct context_buffers *b)
Definition init.c:3696
void init_instance_handle_signals(struct context *c, const struct env_set *env, const unsigned int flags)
Definition init.c:4710
void inherit_context_child(struct context *dest, const struct context *src, struct link_socket *sock)
Definition init.c:4805
void context_clear_2(struct context *c)
Definition init.c:89
void close_context(struct context *c, int sig, unsigned int flags)
Definition init.c:4939
bool do_deferred_options(struct context *c, const uint64_t found, const bool is_update)
Definition init.c:2573
struct context_buffers * init_context_buffers(const struct frame *frame)
Definition init.c:3671
void management_show_net_callback(void *arg, const msglvl_t msglevel)
Definition init.c:4248
#define CC_GC_FREE
Definition init.h:109
#define CC_HARD_USR1_TO_HUP
Definition init.h:111
#define ISC_SERVER
Definition init.h:121
static unsigned int constrain_uint(unsigned int x, unsigned int min, unsigned int max)
Definition integer.h:139
static int min_int(int x, int y)
Definition integer.h:105
static SERVICE_STATUS status
Definition interactive.c:52
@ route
Definition interactive.c:86
@ read
bool event_timeout_trigger(struct event_timeout *et, struct timeval *tv, const int et_const_retry)
This is the principal function for testing and triggering recurring timers.
Definition interval.c:42
#define ETT_DEFAULT
Definition interval.h:222
static void event_timeout_init(struct event_timeout *et, interval_t n, const time_t last)
Initialises a timer struct.
Definition interval.h:172
void hash_iterator_free(struct hash_iterator *hi)
Definition list.c:272
struct hash_element * hash_iterator_next(struct hash_iterator *hi)
Definition list.c:278
void hash_iterator_delete_element(struct hash_iterator *hi)
Definition list.c:310
void hash_iterator_init(struct hash *hash, struct hash_iterator *hi)
Definition list.c:236
struct hash * hash_init(const uint32_t n_buckets, uint64_t(*hash_function)(const void *key, const uint8_t hash_key[HASH_KEY_LEN]), bool(*compare_function)(const void *key1, const void *key2))
Definition list.c:36
void hash_free(struct hash *hash)
Definition list.c:62
struct hash_element * hash_lookup_fast(struct hash *hash, struct hash_bucket *bucket, const void *key, uint64_t hv)
Definition list.c:81
bool hash_add(struct hash *hash, const void *key, void *value, bool replace)
Definition list.c:139
void hash_remove_by_value(struct hash *hash, void *value)
Definition list.c:167
void hash_iterator_init_range(struct hash *hash, struct hash_iterator *hi, uint32_t start_bucket, uint32_t end_bucket)
Definition list.c:215
static bool hash_remove(struct hash *hash, const void *key)
Definition list.h:164
static void * hash_lookup(struct hash *hash, const void *key)
Definition list.h:131
#define HASH_KEY_LEN
Definition list.h:53
static uint32_t hash_n_elements(const struct hash *hash)
Definition list.h:113
static uint32_t hash_n_buckets(const struct hash *hash)
Definition list.h:119
static void hash_add_fast(struct hash *hash, struct hash_bucket *bucket, const void *key, uint64_t hv, void *value)
Definition list.h:149
static struct hash_bucket * hash_bucket(struct hash *hash, uint64_t hv)
Definition list.h:125
static uint64_t hash_value(const struct hash *hash, const void *key)
Definition list.h:107
void management_check_bytecount_server(struct multi_context *multi, struct timeval *timeval)
Definition manage.c:4283
void management_connection_established(struct management *man, struct man_def_auth_context *mdac, const struct env_set *es)
Definition manage.c:3109
void management_notify_client_close(const struct management *man, struct man_def_auth_context *mdac, const struct env_set *es)
Definition manage.c:3119
void management_set_callback(struct management *man, const struct management_callback *cb)
Definition manage.c:2865
void management_learn_addr(struct man_def_auth_context *mdac, const struct mroute_addr *addr, const bool primary)
Definition manage.c:3132
#define MCF_SERVER
Definition manage.h:175
void mbuf_add_item(struct mbuf_set *ms, const struct mbuf_item *item)
Definition mbuf.c:104
struct mbuf_buffer * mbuf_alloc_buf(const struct buffer *buf)
Definition mbuf.c:65
void mbuf_free_buf(struct mbuf_buffer *mb)
Definition mbuf.c:76
void mbuf_dereference_instance(struct mbuf_set *ms, struct multi_instance *mi)
Definition mbuf.c:168
bool mbuf_extract_item(struct mbuf_set *ms, struct mbuf_item *item)
Definition mbuf.c:126
void mbuf_free(struct mbuf_set *ms)
Definition mbuf.c:50
struct mbuf_set * mbuf_init(unsigned int size)
Definition mbuf.c:38
#define MF_UNICAST
Definition mbuf.h:47
static int mbuf_maximum_queued(const struct mbuf_set *ms)
Definition mbuf.h:93
void mroute_addr_mask_host_bits(struct mroute_addr *ma)
Definition mroute.c:319
void mroute_helper_add_iroute46(struct mroute_helper *mh, int netbits)
Definition mroute.c:521
const char * mroute_addr_print_ex(const struct mroute_addr *ma, const unsigned int flags, struct gc_arena *gc)
Definition mroute.c:378
bool mroute_extract_openvpn_sockaddr(struct mroute_addr *addr, const struct openvpn_sockaddr *osaddr, bool use_port)
Definition mroute.c:255
const char * mroute_addr_print(const struct mroute_addr *ma, struct gc_arena *gc)
Definition mroute.c:372
void mroute_helper_del_iroute46(struct mroute_helper *mh, int netbits)
Definition mroute.c:536
bool mroute_learnable_address(const struct mroute_addr *addr, struct gc_arena *gc)
Definition mroute.c:64
bool mroute_addr_compare_function(const void *key1, const void *key2)
Definition mroute.c:366
struct mroute_helper * mroute_helper_init(int ageable_ttl_secs)
Definition mroute.c:483
void mroute_addr_init(struct mroute_addr *addr)
Definition mroute.c:39
uint64_t mroute_addr_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
Definition mroute.c:359
void mroute_helper_free(struct mroute_helper *mh)
Definition mroute.c:552
#define MROUTE_EXTRACT_SUCCEEDED
Definition mroute.h:38
#define MROUTE_EXTRACT_MCAST
Definition mroute.h:40
static unsigned int mroute_extract_addr_from_packet(struct mroute_addr *src, struct mroute_addr *dest, uint16_t vid, const struct buffer *buf, int tunnel_type)
Definition mroute.h:183
#define MR_WITH_NETBITS
Definition mroute.h:70
#define MR_WITH_PROTO
Definition mroute.h:76
static void mroute_extract_in_addr_t(struct mroute_addr *dest, const in_addr_t src)
Definition mroute.h:244
#define MR_ADDR_IPV4
Definition mroute.h:62
#define MR_ONLINK_DCO_ADDR
Definition mroute.h:79
static bool mroute_addr_equal(const struct mroute_addr *a1, const struct mroute_addr *a2)
Definition mroute.h:209
#define MAPF_SHOW_FAMILY
Definition mroute.h:158
#define MROUTE_EXTRACT_BCAST
Definition mroute.h:39
#define MR_ADDR_IPV6
Definition mroute.h:63
#define MR_ADDR_MASK
Definition mroute.h:64
void multi_tcp_instance_specific_free(struct multi_instance *mi)
Definition mtcp.c:92
void multi_tcp_delete_event(struct multi_io *multi_io, event_t event)
Definition mtcp.c:98
bool multi_tcp_instance_specific_init(struct multi_context *m, struct multi_instance *mi)
Definition mtcp.c:70
void multi_tcp_dereference_instance(struct multi_io *multi_io, struct multi_instance *mi)
Definition mtcp.c:107
#define BUF_SIZE(f)
Definition mtu.h:188
static const char * np(const char *str)
Definition multi-auth.c:146
static struct multi_instance * multi_learn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr, const unsigned int flags)
Definition multi.c:1030
static void multi_schedule_context_wakeup(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:2990
bool multi_check_push_ifconfig_ipv6_extra_route(const struct options *o, const struct in6_addr *dest)
Determines if the ifconfig_ipv6_local address falls into the range of the local IP addresses of the V...
Definition multi.c:4512
static void multi_unlearn_in_addr_t(struct multi_context *m, struct multi_instance *mi, in_addr_t a)
Definition multi.c:4380
static void multi_client_connect_early_setup(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:2453
static enum client_connect_return multi_client_connect_real_addr(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
This sets up the client real address (outer tunnel addr) in the hash map for data channel packet.
Definition multi.c:2490
static void multi_reap_free(struct multi_reap *mr)
Definition multi.c:216
static bool ccs_gen_deferred_ret_file(struct multi_instance *mi)
Create a temporary file for the return value of client connect and puts it into the client_connect_de...
Definition multi.c:1915
static void multi_process_float(struct multi_context *m, struct multi_instance *mi, struct link_socket *sock)
Handles peer floating.
Definition multi.c:3213
static void multi_reap_range(const struct multi_context *m, uint32_t start_bucket, uint32_t end_bucket)
Definition multi.c:162
struct multi_instance * multi_create_instance(struct multi_context *m, const struct mroute_addr *real, struct link_socket *sock)
Definition multi.c:722
static void multi_add_iroutes(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:1292
void multi_ifconfig_pool_persist(struct multi_context *m, bool force)
Definition multi.c:151
static enum client_connect_return multi_client_connect_compress_migrate(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Do the necessary modification for doing the compress migrate.
Definition multi.c:2516
static void multi_top_free(struct multi_context *m)
Definition multi.c:3886
static void multi_signal_instance(struct multi_context *m, struct multi_instance *mi, const int sig)
Definition multi.c:3283
void multi_reap_process_dowork(const struct multi_context *m)
Definition multi.c:203
static bool override_locked_username(struct multi_instance *mi)
Overrides the locked username with the username of –override-username.
Definition multi.c:2618
static int management_callback_n_clients(void *arg)
Definition multi.c:3972
bool multi_process_signal(struct multi_context *m)
Definition multi.c:3932
static void multi_select_virtual_addr(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:1423
static bool multi_check_dest_addr_allowed(struct multi_context *m, struct multi_instance *mi, struct mroute_addr *real)
This methods checks if a client instance is allowed to use an address.
Definition multi.c:3133
static void multi_get_timeout(struct multi_context *multi, struct timeval *timeval)
Determines the earliest wakeup interval based on periodic operations.
Definition multi.c:4234
void multi_close_instance_on_signal(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:3271
bool multi_process_post(struct multi_context *m, struct multi_instance *mi, const unsigned int flags)
Perform postprocessing of a VPN tunnel instance.
Definition multi.c:3032
static void multi_connection_established(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:2693
void multi_process_per_second_timers_dowork(struct multi_context *m)
Definition multi.c:3850
static void multi_set_virtual_addr_env(struct multi_instance *mi)
Definition multi.c:1564
static void multi_client_connect_setenv(struct multi_instance *mi)
Definition multi.c:1708
struct multi_instance * multi_get_queue(struct mbuf_set *ms)
Definition multi.c:3703
static void setenv_stats(struct context *c)
Definition multi.c:514
bool multi_process_timeout(struct multi_context *m, const unsigned int mpp_flags)
Definition multi.c:3739
static void multi_unlearn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr)
Definition multi.c:4345
static int management_callback_kill_by_cn(void *arg, const char *del_cn)
Definition multi.c:3979
static void multi_client_disconnect_script(struct multi_instance *mi)
Definition multi.c:534
static bool stale_route_check_trigger(struct multi_context *m)
Definition multi.c:3839
struct multi_instance * lookup_by_cid(struct multi_context *m, const unsigned long cid)
Definition multi.c:4039
static bool management_kill_by_cid(void *arg, const unsigned long cid, const char *kill_msg)
Definition multi.c:4053
static enum client_connect_return multi_client_connect_call_script(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Runs the –client-connect script if one is defined.
Definition multi.c:2226
static void multi_init(struct context *t)
Definition multi.c:270
static void generate_prefix(struct multi_instance *mi)
Definition multi.c:458
static void multi_del_iroutes(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:487
static enum client_connect_return multi_client_connect_call_plugin_v1(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Definition multi.c:2046
enum client_connect_return(* multi_client_connect_handler)(struct multi_context *m, struct multi_instance *mi, bool from_deferred, uint64_t *option_types_found)
Definition multi.c:2598
static void management_delete_event(void *arg, event_t event)
Definition multi.c:4029
static uint64_t cid_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
Definition multi.c:233
static bool multi_client_setup_dco_initial(struct multi_context *m, struct multi_instance *mi, struct gc_arena *gc)
Definition multi.c:2284
enum client_connect_return multi_client_connect_mda(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Definition multi.c:1675
static void multi_uninit(struct multi_context *m)
Definition multi.c:671
const char * multi_instance_string(const struct multi_instance *mi, bool null, struct gc_arena *gc)
Definition multi.c:425
static unsigned int compute_wakeup_sigma(const struct timeval *delta)
Definition multi.c:2966
static bool learn_address_script(const struct multi_context *m, const struct multi_instance *mi, const char *op, const struct mroute_addr *addr)
Definition multi.c:84
static void multi_unicast(struct multi_context *m, const struct buffer *buf, struct multi_instance *mi)
Definition multi.c:2908
static void multi_client_connect_post(struct multi_context *m, struct multi_instance *mi, const char *dc_file, uint64_t *option_types_found)
Definition multi.c:1610
void multi_close_instance(struct multi_context *m, struct multi_instance *mi, bool shutdown)
Definition multi.c:565
static bool management_client_pending_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id, const char *extra, unsigned int timeout)
Definition multi.c:4088
static void multi_push_restart_schedule_exit(struct multi_context *m, bool next_server)
Definition multi.c:3899
static void multi_top_init(struct context *top)
Definition multi.c:3879
static struct tls_session * lookup_session_by_mda_key_id(struct tls_multi *multi, const unsigned int mda_key_id)
Definition multi.c:4070
static bool ccs_gen_config_file(struct multi_instance *mi)
Create a temporary file for the config directives of the client connect script and puts it into the c...
Definition multi.c:2020
static enum client_connect_return multi_client_connect_call_plugin_v2(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Definition multi.c:2136
static void check_stale_routes(struct multi_context *m)
Definition multi.c:1373
bool multi_check_push_ifconfig_extra_route(const struct options *o, in_addr_t dest)
Determines if the ifconfig_push_local address falls into the range of the local IP addresses of the V...
Definition multi.c:4492
static void multi_process_incoming_link_data(struct multi_context *m, bool floated, struct link_socket *sock)
Process incoming data packet from clients.
Definition multi.c:3402
static bool management_client_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id, const bool auth, const char *reason, const char *client_reason, struct buffer_list *cc_config)
Definition multi.c:4115
static void multi_client_connect_late_setup(struct multi_context *m, struct multi_instance *mi, const uint64_t option_types_found)
Definition multi.c:2330
static void multi_bcast(struct multi_context *m, const struct buffer *buf, const struct multi_instance *sender_instance, uint16_t vid)
Definition multi.c:2925
static int management_callback_kill_by_addr(void *arg, const in_addr_t addr, const uint16_t port, const uint8_t proto)
Definition multi.c:4001
static void multi_reap_all(const struct multi_context *m)
Definition multi.c:186
static void multi_print_status(struct multi_context *m, struct status_output *so, const int version)
Definition multi.c:806
void route_quota_exceeded(const struct multi_instance *mi)
Definition multi.c:3793
void ungenerate_prefix(struct multi_instance *mi)
Definition multi.c:475
void multi_assign_peer_id(struct multi_context *m, struct multi_instance *mi)
Assigns a peer-id to a a client and adds the instance to the the instances array of the multi_context...
Definition multi.c:4197
static struct multi_reap * multi_reap_new(uint32_t buckets_per_pass)
Definition multi.c:192
static void multi_delete_dup(struct multi_context *m, struct multi_instance *new_mi)
Definition multi.c:1339
static struct multi_instance * multi_get_instance_by_virtual_addr(struct multi_context *m, const struct mroute_addr *addr, bool cidr_routing)
Definition multi.c:1119
void init_management_callback_multi(struct multi_context *m)
Definition multi.c:4170
static void multi_unlearn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6)
Definition multi.c:4398
static void multi_add_mbuf(struct multi_context *m, struct multi_instance *mi, struct mbuf_buffer *mb)
Definition multi.c:2889
static enum client_connect_return ccs_test_deferred_ret_file(struct multi_instance *mi)
Tests whether the deferred return value file exists and returns the contained return value.
Definition multi.c:1947
static void multi_client_connect_post_plugin(struct multi_context *m, struct multi_instance *mi, const struct plugin_return *pr, uint64_t *option_types_found)
Definition multi.c:1636
static uint32_t reap_buckets_per_pass(uint32_t n_buckets)
Definition multi.c:225
static char * management_get_peer_info(void *arg, const unsigned long cid)
Definition multi.c:4152
static bool multi_client_set_protocol_options(struct context *c)
Calculates the options that depend on the client capabilities based on local options and available pe...
Definition multi.c:1738
void unlearn_ifconfig_ipv6(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:4424
static struct multi_instance * multi_learn_in_addr_t(struct multi_context *m, struct multi_instance *mi, in_addr_t a, int netbits, bool primary)
Definition multi.c:1194
static bool is_exit_restart(int sig)
Definition multi.c:3893
static bool ifconfig_push_constraint_satisfied(const struct context *c)
Definition multi.c:1403
static void set_cc_config(struct multi_instance *mi, struct buffer_list *cc_config)
Definition multi.c:76
void multi_process_drop_outgoing_tun(struct multi_context *m, const unsigned int mpp_flags)
Definition multi.c:3771
static bool cid_compare_function(const void *key1, const void *key2)
Definition multi.c:240
static void multi_client_disconnect_setenv(struct multi_instance *mi)
Definition multi.c:521
void unlearn_ifconfig(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:4412
void update_vhash(struct multi_context *m, struct multi_instance *mi, const char *new_ip, const char *new_ipv6)
Update the vhash with new IP/IPv6 addresses in the multi_context when a push-update message containin...
Definition multi.c:4446
static bool multi_client_generate_tls_keys(struct context *c)
Generates the data channel keys.
Definition multi.c:2307
static enum client_connect_return multi_client_connect_source_ccd(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Try to source a dynamic config file from the –client-config-dir directory.
Definition multi.c:2548
static struct multi_instance * multi_learn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6, int netbits, bool primary)
Definition multi.c:1240
static void management_callback_status(void *arg, const int version, struct status_output *so)
Definition multi.c:3957
static void ccs_delete_config_file(struct multi_instance *mi)
Deletes the temporary file for the config directives of the client connect script and removes it into...
Definition multi.c:1997
static void ccs_delete_deferred_ret_file(struct multi_instance *mi)
Delete the temporary file for the return value of client connect It also removes it from client_conne...
Definition multi.c:1890
static const multi_client_connect_handler client_connect_handlers[]
Definition multi.c:2602
static enum client_connect_return multi_client_connect_script_deferred(struct multi_context *m, struct multi_instance *mi, uint64_t *option_types_found)
Definition multi.c:2185
Header file for server-mode related structures and functions.
client_connect_return
Return values used by the client connect call-back functions.
Definition multi.h:235
@ CC_RET_DEFERRED
Definition multi.h:238
@ CC_RET_FAILED
Definition multi.h:236
@ CC_RET_SKIPPED
Definition multi.h:239
@ CC_RET_SUCCEEDED
Definition multi.h:237
static bool multi_output_queue_ready(const struct multi_context *m, const struct multi_instance *mi)
Definition multi.h:400
#define MULTI_PREFIX_MAX_LENGTH
Definition multi.h:44
#define MULTI_CHECK_SIG(m)
Definition multi.h:710
#define REAP_MIN
Definition multi.h:563
static void set_prefix(struct multi_instance *mi)
Definition multi.h:532
static void multi_route_del(struct multi_route *route)
Definition multi.h:491
static void multi_reap_process(const struct multi_context *m)
Definition multi.h:577
static void route_quota_inc(struct multi_instance *mi)
Definition multi.h:444
void multi_process_incoming_dco(dco_context_t *dco)
Process an incoming DCO message (from kernel space).
#define MULTI_ROUTE_CACHE
Definition multi.h:250
static void clear_prefix(void)
Definition multi.h:544
static bool multi_route_defined(const struct multi_context *m, const struct multi_route *r)
Definition multi.h:500
#define REAP_DIVISOR
Definition multi.h:562
#define MULTI_CACHE_ROUTE_TTL
Definition multi.h:570
#define MPP_CLOSE_ON_SIGNAL
Definition multi.h:285
#define REAP_MAX
Definition multi.h:564
static void multi_instance_dec_refcount(struct multi_instance *mi)
Definition multi.h:481
static void multi_instance_inc_refcount(struct multi_instance *mi)
Definition multi.h:475
static void multi_get_timeout_instance(struct multi_context *m, struct timeval *dest)
Definition multi.h:605
#define CLIENT_CONNECT_OPT_MASK
Definition multi.h:665
static void multi_set_pending(struct multi_context *m, struct multi_instance *mi)
Definition multi.h:713
#define MULTI_ROUTE_AGEABLE
Definition multi.h:251
#define MPP_RECORD_TOUCH
Definition multi.h:286
#define MULTI_ROUTE_PERMANENT
Definition multi.h:252
#define MPP_PRE_SELECT
Definition multi.h:284
static void multi_process_per_second_timers(struct multi_context *m)
Definition multi.h:586
static bool route_quota_test(const struct multi_instance *mi)
Definition multi.h:457
struct multi_io * multi_io_init(const int maxclients)
Definition multi_io.c:108
void multi_io_process_io(struct multi_context *m)
Definition multi_io.c:451
void multi_io_free(struct multi_io *multi_io)
Definition multi_io.c:147
int multi_io_wait(struct multi_context *m)
Definition multi_io.c:188
void multi_io_action(struct multi_context *m, struct multi_instance *mi, int action, bool poll)
Definition multi_io.c:576
#define TA_TIMEOUT
Definition multi_io.h:45
#define CLEAR(x)
Definition basic.h:32
#define M_OPTERR
Definition error.h:101
static bool check_debug_level(msglvl_t level)
Definition error.h:253
#define M_USAGE
Definition error.h:107
#define M_NONFATAL
Definition error.h:91
#define dmsg(flags,...)
Definition error.h:164
#define msg(flags,...)
Definition error.h:152
unsigned int msglvl_t
Definition error.h:77
#define ASSERT(x)
Definition error.h:221
#define M_WARN
Definition error.h:92
#define M_ERRNO
Definition error.h:95
static bool is_cas_pending(enum multi_status cas)
Definition openvpn.h:210
#define MAX_PEER_ID
Definition openvpn.h:552
#define CM_TOP
Definition openvpn.h:480
const char title_string[]
Definition options.c:73
bool has_udp_in_local_list(const struct options *options)
Definition options.c:7950
#define MODE_SERVER
Definition options.h:265
static bool dco_enabled(const struct options *o)
Returns whether the current configuration has dco enabled.
Definition options.h:972
void options_string_import(struct options *options, const char *config, const msglvl_t msglevel, const uint64_t permission_mask, uint64_t *option_types_found, struct env_set *es)
#define OPT_P_COMP
Definition options.h:742
void options_server_import(struct options *o, const char *filename, msglvl_t msglevel, uint64_t permission_mask, uint64_t *option_types_found, struct env_set *es)
const char * time_string(time_t t, tv_usec_t usec, bool show_usec, struct gc_arena *gc)
Definition otime.c:104
struct frequency_limit * frequency_limit_init(int max, int per)
Definition otime.c:137
time_t now
Definition otime.c:33
void frequency_limit_free(struct frequency_limit *f)
Definition otime.c:152
static int openvpn_gettimeofday(struct timeval *tv, void *tz)
Definition otime.h:71
static void tv_add(struct timeval *dest, const struct timeval *src)
Definition otime.h:129
@ OVPN_DEL_PEER_REASON_EXPIRED
@ OVPN_DEL_PEER_REASON_TRANSPORT_DISCONNECT
@ OVPN_DEL_PEER_REASON_TRANSPORT_ERROR
@ OVPN_DEL_PEER_REASON_USERSPACE
@ OVPN_CMD_FLOAT_PEER
@ OVPN_CMD_SWAP_KEYS
@ OVPN_CMD_DEL_PEER
bool platform_test_file(const char *filename)
Return true if filename can be opened for read.
Definition platform.c:681
const char * platform_create_temp_file(const char *directory, const char *prefix, struct gc_arena *gc)
Create a temporary file in directory, returns the filename of the created file.
Definition platform.c:540
const char * platform_gen_path(const char *directory, const char *filename, struct gc_arena *gc)
Put a directory and filename together.
Definition platform.c:617
bool platform_unlink(const char *filename)
Definition platform.c:487
void plugin_return_free(struct plugin_return *pr)
Definition plugin.c:986
void plugin_return_get_column(const struct plugin_return *src, struct plugin_return *dest, const char *colname)
Definition plugin.c:972
bool plugin_defined(const struct plugin_list *pl, const int type)
Definition plugin.c:904
static void plugin_return_init(struct plugin_return *pr)
Definition plugin.h:163
static int plugin_call(const struct plugin_list *pl, const int type, const struct argv *av, struct plugin_return *pr, struct env_set *es)
Definition plugin.h:195
static bool plugin_return_defined(const struct plugin_return *pr)
Definition plugin.h:157
ifconfig_pool_handle ifconfig_pool_acquire(struct ifconfig_pool *pool, in_addr_t *local, in_addr_t *remote, struct in6_addr *remote_ipv6, const char *common_name)
Definition pool.c:297
bool ifconfig_pool_release(struct ifconfig_pool *pool, ifconfig_pool_handle hand, const bool hard)
Definition pool.c:349
void ifconfig_pool_write(struct ifconfig_pool_persist *persist, const struct ifconfig_pool *pool)
Definition pool.c:711
bool ifconfig_pool_write_trigger(struct ifconfig_pool_persist *persist)
Definition pool.c:572
void ifconfig_pool_free(struct ifconfig_pool *pool)
Definition pool.c:281
void ifconfig_pool_read(struct ifconfig_pool_persist *persist, struct ifconfig_pool *pool)
Definition pool.c:585
struct ifconfig_pool * ifconfig_pool_init(const bool ipv4_pool, enum pool_type type, in_addr_t start, in_addr_t end, const bool duplicate_cn, const bool ipv6_pool, const struct in6_addr ipv6_base, const int ipv6_netbits)
Definition pool.c:140
pool_type
Definition pool.h:35
@ IFCONFIG_POOL_30NET
Definition pool.h:36
@ IFCONFIG_POOL_INDIV
Definition pool.h:37
#define DEV_TYPE_TAP
Definition proto.h:36
#define DEV_TYPE_UNDEF
Definition proto.h:34
#define TOP_NET30
Definition proto.h:41
#define DEV_TYPE_TUN
Definition proto.h:35
#define TOP_P2P
Definition proto.h:42
#define TOP_SUBNET
Definition proto.h:43
int process_incoming_push_request(struct context *c)
Definition push.c:986
void push_option(struct options *o, const char *opt, msglvl_t msglevel)
Definition push.c:896
void send_restart(struct context *c, const char *kill_msg)
Definition push.c:494
bool send_auth_pending_messages(struct tls_multi *tls_multi, struct tls_session *session, const char *extra, unsigned int timeout)
Sends the auth pending control messages to a client.
Definition push.c:433
void remove_iroutes_from_push_route_list(struct options *o)
Definition push.c:1147
bool management_callback_send_push_update_by_cid(void *arg, unsigned long cid, const char *options)
Definition push_util.c:365
bool management_callback_send_push_update_broadcast(void *arg, const char *options)
Definition push_util.c:357
void initial_rate_limit_free(struct initial_packet_rate_limit *irl)
free the initial-packet rate limiter structure
struct initial_packet_rate_limit * initial_rate_limit_init(int max_per_period, int period_length)
allocate and initialize the initial-packet rate limiter structure
bool ipv6_net_contains_host(const struct in6_addr *network, unsigned int bits, const struct in6_addr *host)
check whether an IPv6 host address is covered by a given network/bits
Definition route.c:705
static int openvpn_run_script(const struct argv *a, const struct env_set *es, const unsigned int flags, const char *hook)
Will run a script and return the exit code of the script if between 0 and 255, -1 otherwise.
Definition run_command.h:89
void schedule_remove_entry(struct schedule *s, struct schedule_entry *e)
Definition schedule.c:388
struct schedule * schedule_init(void)
Definition schedule.c:373
void schedule_free(struct schedule *s)
Definition schedule.c:382
static void schedule_add_entry(struct schedule *s, struct schedule_entry *e, const struct timeval *tv, unsigned int sigma)
Add a struct schedule_entry to the scheduler btree or update an existing entry with a new wakeup time...
Definition schedule.h:98
static bool session_id_defined(const struct session_id *sid1)
Definition session_id.h:53
static uint64_t session_id_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
Definition sid_hash.h:81
static bool session_id_hash_equal(const void *sid1, const void *sid2)
Definition sid_hash.h:89
static bool multi_hash_sid_remove(struct multi_context *m, const struct session_id *sid)
Definition sid_hash.h:59
int signal_reset(struct signal_info *si, int signum)
Clear the signal if its current value equals signum.
Definition sig.c:262
void remap_signal(struct context *c)
Definition sig.c:588
void throw_signal(const int signum)
Throw a hard signal.
Definition sig.c:175
void print_signal(const struct signal_info *si, const char *title, msglvl_t msglevel)
Definition sig.c:290
void register_signal(struct signal_info *si, int signum, const char *signal_text)
Register a soft signal in the signal_info struct si respecting priority.
Definition sig.c:228
#define IS_SIG(c)
Definition sig.h:47
void setenv_trusted(struct env_set *es, const struct link_socket_info *info)
Definition socket.c:1855
void setenv_in_addr_t(struct env_set *es, const char *name_prefix, in_addr_t addr, const unsigned int flags)
void setenv_in6_addr(struct env_set *es, const char *name_prefix, const struct in6_addr *addr, const unsigned int flags)
const char * print_in6_addr(struct in6_addr a6, unsigned int flags, struct gc_arena *gc)
const char * print_in_addr_t(in_addr_t addr, unsigned int flags, struct gc_arena *gc)
#define IA_EMPTY_IF_UNDEF
Definition socket_util.h:89
static bool proto_is_dgram(int proto)
Return if the protocol is datagram (UDP).
#define SA_SET_IF_NONZERO
void tls_update_remote_addr(struct tls_multi *multi, const struct link_socket_actual *addr)
Updates remote address in TLS sessions.
Definition ssl.c:4274
void tls_session_soft_reset(struct tls_multi *tls_multi)
Definition ssl.c:1833
bool tls_session_update_crypto_params(struct tls_multi *multi, struct tls_session *session, struct options *options, struct frame *frame, struct frame *frame_fragment, struct link_socket_info *lsi, dco_context_t *dco)
Update TLS session crypto parameters (cipher and auth) and derive data channel keys based on the supp...
Definition ssl.c:1705
#define IV_PROTO_CC_EXIT_NOTIFY
Support for explicit exit notify via control channel This also includes support for the protocol-flag...
Definition ssl.h:102
#define IV_PROTO_DATA_EPOCH
Support the extended packet id and epoch format for data channel packets.
Definition ssl.h:111
#define IV_PROTO_DATA_V2
Support P_DATA_V2.
Definition ssl.h:80
#define IV_PROTO_TLS_KEY_EXPORT
Supports key derivation via TLS key material exporter [RFC5705].
Definition ssl.h:87
#define IV_PROTO_DYN_TLS_CRYPT
Support to dynamic tls-crypt (renegotiation with TLS-EKM derived tls-crypt key).
Definition ssl.h:108
#define IV_PROTO_REQUEST_PUSH
Assume client will send a push request and server does not need to wait for a push-request to send a ...
Definition ssl.h:84
#define IV_PROTO_NCP_P2P
Support doing NCP in P2P mode.
Definition ssl.h:95
@ CAS_CONNECT_DONE
Definition ssl_common.h:593
@ CAS_PENDING_DEFERRED
Waiting on an async option import handler.
Definition ssl_common.h:583
@ CAS_WAITING_AUTH
Initial TLS connection established but deferred auth is not yet finished.
Definition ssl_common.h:581
@ CAS_PENDING_DEFERRED_PARTIAL
at least handler succeeded but another is still pending
Definition ssl_common.h:584
@ CAS_PENDING
Options import (Connect script/plugin, ccd,...).
Definition ssl_common.h:582
@ CAS_NOT_CONNECTED
Definition ssl_common.h:580
@ CAS_FAILED
Option import failed or explicitly denied the client.
Definition ssl_common.h:585
@ KS_AUTH_FALSE
Key state is not authenticated.
Definition ssl_common.h:154
@ KS_AUTH_DEFERRED
Key state authentication is being deferred, by async auth.
Definition ssl_common.h:155
static const struct key_state * get_primary_key(const struct tls_multi *multi)
gets an item of key_state objects in the order they should be scanned by data channel modules.
Definition ssl_common.h:757
#define SSLF_USERNAME_AS_COMMON_NAME
Definition ssl_common.h:425
char * ncp_get_best_cipher(const char *server_list, const char *peer_info, const char *remote_cipher, struct gc_arena *gc)
Iterates through the ciphers in server_list and return the first cipher that is also supported by the...
Definition ssl_ncp.c:238
const char * tls_peer_ncp_list(const char *peer_info, struct gc_arena *gc)
Returns the support cipher list from the peer according to the IV_NCP and IV_CIPHER values in peer_in...
Definition ssl_ncp.c:217
const char * ncp_expanded_ciphers(struct options *o, struct gc_arena *gc)
returns the o->ncp_ciphers in brackets, e.g.
Definition ssl_ncp.c:628
Control Channel SSL/Data dynamic negotiation Module This file is split from ssl.h to be able to unit ...
SSL utility functions.
static unsigned int extract_iv_proto(const char *peer_info)
Extracts the IV_PROTO variable and returns its value or 0 if it cannot be extracted.
Definition ssl_util.h:77
bool ssl_verify_username_length(struct tls_session *session, const char *username)
Checks if the username length is valid to use.
bool tls_authenticate_key(struct tls_multi *multi, const unsigned int mda_key_id, const bool auth, const char *client_reason)
bool cert_hash_compare(const struct cert_hash_set *chs1, const struct cert_hash_set *chs2)
Compares certificates hashes, returns true if hashes are equal.
Definition ssl_verify.c:229
void tls_lock_cert_hash_set(struct tls_multi *multi)
Locks the certificate hash set used in the given tunnel.
Definition ssl_verify.c:286
void tls_lock_common_name(struct tls_multi *multi)
Locks the common name field for the given tunnel.
Definition ssl_verify.c:132
const char * tls_username(const struct tls_multi *multi, const bool null)
Returns the username field for the given tunnel.
Definition ssl_verify.c:172
void set_common_name(struct tls_session *session, const char *common_name)
Sets the common name field for the given tunnel.
Definition ssl_verify.c:85
void auth_set_client_reason(struct tls_multi *multi, const char *client_reason)
Sets the reason why authentication of a client failed.
Definition ssl_verify.c:814
const char * tls_common_name(const struct tls_multi *multi, const bool null)
Returns the common name field for the given tunnel.
Definition ssl_verify.c:107
Control Channel Verification Module.
bool status_trigger(struct status_output *so)
Definition status.c:123
void status_printf(struct status_output *so, const char *format,...)
Definition status.c:212
struct status_output * status_open(const char *filename, const int refresh_freq, const int msglevel, const struct virtual_output *vout, const unsigned int flags)
Definition status.c:59
void status_flush(struct status_output *so)
Definition status.c:147
void status_reset(struct status_output *so)
Definition status.c:138
bool status_close(struct status_output *so)
Definition status.c:178
Definition argv.h:35
One node in a buffer_list linked list.
Definition buffer.h:2163
struct buffer_entry * next
Pointer to the next node, or NULL.
Definition buffer.h:2165
struct buffer buf
The buffer stored in this list node.
Definition buffer.h:2164
A singly-linked list of buffers, with head/tail pointers for O(1) push.
Definition buffer.h:2170
struct buffer_entry * head
Next item to pop/peek.
Definition buffer.h:2171
Wrapper structure for dynamically allocated memory.
Definition buffer.h:71
uint8_t * data
Pointer to the allocated memory.
Definition buffer.h:78
int len
Length in bytes of the actual content within the allocated memory.
Definition buffer.h:76
Detached client connection state.
Definition multi.h:71
uint64_t option_types_found
Definition multi.h:76
char * config_file
The temporary file name that contains the config directives returned by the client-connect script.
Definition multi.h:88
char * deferred_ret_file
The temporary file name that contains the return status of the client-connect script if it exits with...
Definition multi.h:82
unsigned int flags
Definition comp.h:77
int explicit_exit_notification
Definition options.h:152
int fragment
Definition options.h:143
struct ifconfig_pool_persist * ifconfig_pool_persist
Definition openvpn.h:198
struct status_output * status_output
Definition openvpn.h:186
struct tuntap * tuntap
Tun/tap virtual network interface.
Definition openvpn.h:173
bool push_request_received
Definition openvpn.h:424
counter_type link_read_bytes
Definition openvpn.h:267
counter_type link_write_bytes
Definition openvpn.h:270
bool push_ifconfig_ipv6_defined
Definition openvpn.h:431
struct fragment_master * fragment
Definition openvpn.h:253
bool push_ifconfig_defined
Definition openvpn.h:425
counter_type dco_read_bytes
Definition openvpn.h:268
struct man_def_auth_context mda_context
Definition openvpn.h:450
counter_type dco_write_bytes
Definition openvpn.h:271
struct env_set * es
Definition openvpn.h:420
struct tls_multi * tls_multi
TLS state structure for this VPN tunnel.
Definition openvpn.h:324
struct frame frame
Definition openvpn.h:249
struct in6_addr push_ifconfig_ipv6_remote
Definition openvpn.h:434
struct link_socket_actual from
Definition openvpn.h:246
struct frame frame_fragment
Definition openvpn.h:254
int push_ifconfig_ipv6_netbits
Definition openvpn.h:433
struct buffer to_link
Definition openvpn.h:377
struct buffer to_tun
Definition openvpn.h:376
struct in6_addr push_ifconfig_ipv6_local
Definition openvpn.h:432
struct link_socket ** link_sockets
Definition openvpn.h:238
in_addr_t push_ifconfig_local_alias
Definition openvpn.h:429
struct link_socket_info ** link_socket_infos
Definition openvpn.h:239
struct link_socket_actual * to_link_addr
Definition openvpn.h:245
in_addr_t push_ifconfig_remote_netmask
Definition openvpn.h:428
struct buffer buf
Definition openvpn.h:375
struct timeval timeval
Time to next event of timers and similar.
Definition openvpn.h:396
struct event_set * event_set
Definition openvpn.h:231
struct context_buffers * buffers
Definition openvpn.h:367
in_addr_t push_ifconfig_local
Definition openvpn.h:427
Contains all state information for one tunnel.
Definition openvpn.h:471
int mode
Role of this context within the OpenVPN process.
Definition openvpn.h:484
struct multi_context * multi
Pointer to the main P2MP context.
Definition openvpn.h:489
bool did_dco_iroutes
Whether DCO iroutes have been installed.
Definition openvpn.h:510
struct signal_info * sig
Internal error signaling object.
Definition openvpn.h:500
openvpn_net_ctx_t net_ctx
Networking API opaque context.
Definition openvpn.h:498
struct plugin_list * plugins
List of plug-ins.
Definition openvpn.h:502
struct context_2 c2
Level 2 context.
Definition openvpn.h:516
struct env_set * es
Set of environment variables.
Definition openvpn.h:496
struct options options
Options loaded from command line or configuration file.
Definition openvpn.h:472
struct context_1 c1
Level 1 context.
Definition openvpn.h:515
Security parameter state for processing data channel packets.
Definition crypto.h:293
struct key_ctx_bi key_ctx_bi
OpenSSL cipher and HMAC contexts for both sending and receiving directions.
Definition crypto.h:294
int signal_received
Definition multi.h:62
struct timeval wakeup
Definition multi.h:63
union event_arg::@352313260244035237115140212234220346176163201310 u
struct multi_instance * mi
Definition event.h:144
event_arg_t type
Definition event.h:141
struct buffer outgoing
Buffer containing the remaining parts of the fragmented packet being sent.
Definition fragment.h:172
Packet geometry parameters.
Definition mtu.h:113
struct frame::@074234134026241341315172337061247271261307273127 buf
int payload_size
the maximum size that a payload that our buffers can hold from either tun device or network link.
Definition mtu.h:118
int headroom
the headroom in the buffer, this is choosen to allow all potential header to be added before the pack...
Definition mtu.h:124
Garbage collection arena used to keep track of dynamically allocated memory.
Definition buffer.h:127
void * value
Definition list.h:41
const void * key
Definition list.h:42
Definition list.h:56
struct iroute_ipv6 * next
Definition route.h:271
unsigned int netbits
Definition route.h:270
struct in6_addr network
Definition route.h:269
in_addr_t network
Definition route.h:262
int netbits
Definition route.h:263
struct iroute * next
Definition route.h:264
Container for bidirectional cipher and HMAC key material.
Definition crypto.h:240
bool initialized
Definition crypto.h:285
Security parameter state of one TLS and data channel key session.
Definition ssl_common.h:208
struct auth_deferred_status plugin_auth
Definition ssl_common.h:268
unsigned int mda_key_id
Definition ssl_common.h:263
struct auth_deferred_status script_auth
Definition ssl_common.h:269
enum ks_auth_state authenticated
Definition ssl_common.h:259
Container for unidirectional cipher and HMAC key material.
Definition crypto.h:152
unsigned long cid
Definition manage.h:64
char *(* get_peer_info)(void *arg, const unsigned long cid)
Definition manage.h:191
bool(* client_auth)(void *arg, const unsigned long cid, const unsigned int mda_key_id, const bool auth, const char *reason, const char *client_reason, struct buffer_list *cc_config)
Definition manage.h:186
int(* kill_by_addr)(void *arg, const in_addr_t addr, const uint16_t port, const uint8_t proto)
Definition manage.h:181
void(* delete_event)(void *arg, event_t event)
Definition manage.h:182
bool(* push_update_broadcast)(void *arg, const char *options)
Definition manage.h:199
bool(* push_update_by_cid)(void *arg, unsigned long cid, const char *options)
Definition manage.h:200
bool(* client_pending_auth)(void *arg, const unsigned long cid, const unsigned int kid, const char *extra, unsigned int timeout)
Definition manage.h:189
int(* n_clients)(void *arg)
Definition manage.h:183
void(* status)(void *arg, const int version, struct status_output *so)
Definition manage.h:178
void(* show_net)(void *arg, const msglvl_t msglevel)
Definition manage.h:179
unsigned int flags
Definition manage.h:176
int(* kill_by_cn)(void *arg, const char *common_name)
Definition manage.h:180
bool(* kill_by_cid)(void *arg, const unsigned long cid, const char *kill_msg)
Definition manage.h:185
unsigned int flags
Definition mbuf.h:48
struct buffer buf
Definition mbuf.h:44
struct mbuf_buffer * buffer
Definition mbuf.h:53
struct multi_instance * instance
Definition mbuf.h:54
uint16_t vid
Definition mroute.h:94
uint8_t addr[OPENVPN_ETH_ALEN]
Definition mroute.h:93
uint8_t proto
Definition mroute.h:84
uint8_t type
Definition mroute.h:85
struct mroute_addr::@201361377123046052363312040316220023015150251140::@324142022017217332104337017226063207330251301017 v6
in_port_t port
Definition mroute.h:99
uint8_t len
Definition mroute.h:83
struct mroute_addr::@201361377123046052363312040316220023015150251140::@363302133323255313212060077174173034011260361234 v4
uint8_t netbits
Definition mroute.h:86
unsigned int cache_generation
Definition mroute.h:133
uint8_t net_len[MR_HELPER_NET_LEN]
Definition mroute.h:136
int n_net_len
Definition mroute.h:135
Main OpenVPN server state structure.
Definition multi.h:170
int n_clients
Definition multi.h:202
struct mroute_addr local
Definition multi.h:197
struct schedule * schedule
Definition multi.h:187
struct mbuf_set * mbuf
Set of buffers for passing data channel packets between VPN tunnel instances.
Definition multi.h:188
struct initial_packet_rate_limit * initial_rate_limiter
Definition multi.h:194
struct deferred_signal_schedule_entry deferred_shutdown_signal
Definition multi.h:228
uint32_t max_peerid
highest currently allocated peer-id and maximum allocated/valid index in instances
Definition multi.h:174
struct multi_reap * reaper
Definition multi.h:196
struct multi_io * multi_io
I/O state and events tracker.
Definition multi.h:191
struct hash * hash
VPN tunnel instances indexed by real address of the remote peer.
Definition multi.h:177
struct hash * cid_hash
Definition multi.h:205
unsigned long cid_counter
Definition multi.h:206
struct event_timeout stale_routes_check_et
Definition multi.h:221
int tcp_queue_limit
Definition multi.h:200
struct ifconfig_pool * ifconfig_pool
Definition multi.h:192
struct frequency_limit * new_connection_limiter
Definition multi.h:193
uint32_t max_clients
Definition multi.h:199
struct context top
Storage structure for process-wide configuration.
Definition multi.h:215
int status_file_version
Definition multi.h:201
struct multi_instance * pending
Definition multi.h:209
struct hash * vhash
VPN tunnel instances indexed by virtual address of remote hosts.
Definition multi.h:179
struct multi_instance ** instances
Array of multi_instances with the size of max_clients.
Definition multi.h:171
struct multi_instance ** mpp_touched
Definition multi.h:211
bool enable_c2c
Definition multi.h:198
struct hash * sid_hash
TLS sessions indexed by the peer's session id.
Definition multi.h:181
struct multi_instance * earliest_wakeup
Definition multi.h:210
struct mroute_helper * route_helper
Definition multi.h:195
Server-mode state structure for one single VPN tunnel.
Definition multi.h:102
struct buffer_list * cc_config
Definition multi.h:145
struct client_connect_defer_state client_connect_defer_state
Definition multi.h:152
bool did_cid_hash
Definition multi.h:144
time_t created
Time at which a VPN tunnel instance was created.
Definition multi.h:116
in_addr_t reporting_addr
Definition multi.h:131
char msg_prefix[MULTI_PREFIX_MAX_LENGTH]
Definition multi.h:124
struct mroute_addr real
External network address of the remote peer.
Definition multi.h:121
bool did_iroutes
Definition multi.h:147
ifconfig_pool_handle vaddr_handle
Definition multi.h:123
bool did_real_hash
Indicates that the real address/port of the client is hashed in the multi_context m->hash table.
Definition multi.h:136
struct gc_arena gc
Definition multi.h:112
struct in6_addr reporting_addr_ipv6
Definition multi.h:132
struct timeval wakeup
Definition multi.h:120
struct event_arg ev_arg
this struct will store a pointer to either mi or link_socket, depending on the event type,...
Definition multi.h:107
struct context context
The context structure storing state for this VPN tunnel.
Definition multi.h:150
struct session_id sid_hashed_value
If this is multi_instance is hashed in the sid lookup table the session id here is a non-null session...
Definition multi.h:141
int n_clients_delta
Definition multi.h:148
time_t last_call
Definition multi.h:55
uint32_t buckets_per_pass
Definition multi.h:54
uint32_t bucket_base
Definition multi.h:53
struct mroute_addr addr
Definition multi.h:247
time_t last_reference
Definition multi.h:256
unsigned int cache_generation
Definition multi.h:255
unsigned int flags
Definition multi.h:253
struct multi_instance * instance
Definition multi.h:248
union openvpn_sockaddr::@051240265251124304325377241125360350250341115171 addr
struct sockaddr_in in4
Definition socket_util.h:43
struct compress_options comp
Definition options.h:410
uint32_t sid_hash_size
Definition options.h:501
int push_ifconfig_ipv6_netbits
Definition options.h:524
int max_routes_per_client
Definition options.h:537
const char * ncp_ciphers_conf
The original ncp_ciphers specified by the user in the configuration.
Definition options.h:580
int status_file_version
Definition options.h:407
in_addr_t push_ifconfig_constraint_network
Definition options.h:519
const char * tmp_dir
Definition options.h:466
unsigned int imported_protocol_flags
Definition options.h:724
int stale_routes_ageing_time
Definition options.h:539
bool duplicate_cn
Definition options.h:528
uint32_t real_hash_size
Definition options.h:499
bool use_peer_id
Whether the data channel uses the DATA_V2 header (peer-id).
Definition options.h:704
in_addr_t ifconfig_pool_netmask
Definition options.h:491
const char * ifconfig_ipv6_local
Definition options.h:329
int cf_max
Definition options.h:530
const char * dev_type
Definition options.h:323
bool push_ifconfig_defined
Definition options.h:514
bool ifconfig_pool_defined
Definition options.h:488
bool vlan_tagging
Definition options.h:713
in_addr_t ifconfig_pool_end
Definition options.h:490
bool ifconfig_ipv6_pool_defined
Definition options.h:495
uint32_t max_clients
Definition options.h:536
const char * client_disconnect_script
Definition options.h:503
int n_bcast_buf
Definition options.h:510
const char * ifconfig_local
Definition options.h:327
struct connection_entry ce
Definition options.h:294
struct iroute_ipv6 * iroutes_ipv6
Definition options.h:513
in_addr_t push_ifconfig_local_alias
Definition options.h:517
int topology
Definition options.h:326
const char * ncp_ciphers
Definition options.h:581
uint32_t virtual_hash_size
Definition options.h:500
const char * learn_address_script
Definition options.h:504
const char * ciphername
Definition options.h:576
int cf_initial_max
Definition options.h:533
int stale_routes_check_interval
Definition options.h:538
uint16_t vlan_pvid
Definition options.h:715
int mode
Definition options.h:266
int ifconfig_ipv6_pool_netbits
Definition options.h:497
in_addr_t push_ifconfig_constraint_netmask
Definition options.h:520
bool enable_ncp_fallback
If defined fall back to ciphername if NCP fails.
Definition options.h:577
in_addr_t push_ifconfig_local
Definition options.h:515
struct gc_arena gc
Definition options.h:258
bool push_ifconfig_constraint_defined
Definition options.h:518
int cf_initial_per
Definition options.h:534
bool force_key_material_export
Definition options.h:711
struct iroute * iroutes
Definition options.h:512
struct in6_addr push_ifconfig_ipv6_remote
Definition options.h:525
const char * client_connect_script
Definition options.h:502
bool push_ifconfig_ipv6_defined
Definition options.h:522
int tcp_queue_limit
Definition options.h:511
const char * override_username
Definition options.h:509
struct in6_addr push_ifconfig_ipv6_local
Definition options.h:523
const char * ifconfig_remote_netmask
Definition options.h:328
bool enable_c2c
Definition options.h:527
int cf_per
Definition options.h:531
in_addr_t ifconfig_pool_start
Definition options.h:489
in_addr_t push_ifconfig_remote_netmask
Definition options.h:516
const char * dev
Definition options.h:322
struct in6_addr ifconfig_ipv6_pool_base
Definition options.h:496
const char * client_config_dir
Definition options.h:506
int ifconfig_ipv6_netbits
Definition options.h:330
struct openvpn_plugin_string_list * list[MAX_PLUGINS]
Definition plugin.h:106
Definition schedule.h:41
const char * signal_text
Definition sig.h:44
volatile int signal_received
Definition sig.h:42
Security parameter state for a single VPN tunnel.
Definition ssl_common.h:611
char * auth_token_initial
The first auth-token we sent to a client.
Definition ssl_common.h:683
bool remote_usescomp
remote announced comp-lzo in OCC string
Definition ssl_common.h:705
char * peer_info
A multi-line string of general-purpose info received from peer over control channel.
Definition ssl_common.h:672
char * remote_ciphername
cipher specified in peer's config file
Definition ssl_common.h:704
char * locked_username
The locked username is the username we assume the client is using.
Definition ssl_common.h:649
enum multi_status multi_state
Definition ssl_common.h:632
struct tls_session session[TM_SIZE]
Array of tls_session objects representing control channel sessions with the remote peer.
Definition ssl_common.h:713
struct cert_hash_set * locked_cert_hash_set
Definition ssl_common.h:655
char * locked_cn
Our locked common name, username, and cert hashes (cannot change during the life of this tls_multi ob...
Definition ssl_common.h:644
bool use_peer_id
Definition ssl_common.h:701
char * locked_original_username
The username that client initially used before being overridden by –override-user.
Definition ssl_common.h:653
uint32_t rx_peer_id
Definition ssl_common.h:699
int dco_peer_id
This is the handle that DCO uses to identify this session with the kernel.
Definition ssl_common.h:725
bool data_epoch_supported
whether our underlying data channel supports new data channel features (epoch keys with AEAD tag at t...
Definition ssl_common.h:379
Security parameter state of a single session within a VPN tunnel.
Definition ssl_common.h:489
struct key_state key[KS_SIZE]
Definition ssl_common.h:524
struct tls_options * opt
Definition ssl_common.h:491
in_addr_t local
Definition tun.h:208
struct in6_addr local_ipv6
Definition tun.h:211
dco_context_t dco
Definition tun.h:247
in_addr_t remote_netmask
Definition tun.h:209
char username[USER_PASS_LEN]
Definition misc.h:70
#define SIGHUP
Definition syshead.h:55
#define SIGINT
Definition syshead.h:56
#define SIGTERM
Definition syshead.h:59
#define SIGUSR1
Definition syshead.h:57
uint32_t in_addr_t
Definition syshead.h:52
#define SIGUSR2
Definition syshead.h:58
static int cleanup(void **state)
struct gc_arena gc
Definition test_ssl.c:122
int dev_type_enum(const char *dev, const char *dev_type)
Definition tun.c:521
#define TUNNEL_TOPOLOGY(tt)
Definition tun.h:185
#define TUNNEL_TYPE(tt)
Definition tun.h:182
int16_t vlan_decapsulate(const struct context *c, struct buffer *buf)
Definition vlan.c:81
bool vlan_is_tagged(const struct buffer *buf)
Definition vlan.c:261