OpenVPN
multi.c
Go to the documentation of this file.
1/*
2 * OpenVPN -- An application to securely tunnel IP networks
3 * over a single TCP/UDP port, with support for SSL/TLS-based
4 * session authentication and key exchange,
5 * packet encryption, packet authentication, and
6 * packet compression.
7 *
8 * Copyright (C) 2002-2026 OpenVPN Inc <sales@openvpn.net>
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License version 2
12 * as published by the Free Software Foundation.
13 *
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 * GNU General Public License for more details.
18 *
19 * You should have received a copy of the GNU General Public License along
20 * with this program; if not, see <https://www.gnu.org/licenses/>.
21 */
22
23#ifdef HAVE_CONFIG_H
24#include "config.h"
25#endif
26
27#ifdef HAVE_SYS_INOTIFY_H
28#include <sys/inotify.h>
29#define INOTIFY_EVENT_BUFFER_SIZE 16384
30#endif
31
32#include "syshead.h"
33
34#include "forward.h"
35#include "multi.h"
36#include "push.h"
37#include "run_command.h"
38#include "otime.h"
39#include "gremlin.h"
40#include "ssl_verify.h"
41#include "ssl_ncp.h"
42#include "vlan.h"
43#include "auth_token.h"
44#include "route.h"
45#include <inttypes.h>
46#include <string.h>
47
48#include "memdbg.h"
49
50
51#include "crypto_backend.h"
52#include "ssl_util.h"
53#include "dco.h"
54#include "reflect_filter.h"
55
56/*#define MULTI_DEBUG_EVENT_LOOP*/
57
58#ifdef MULTI_DEBUG_EVENT_LOOP
59static const char *
60id(struct multi_instance *mi)
61{
62 if (mi)
63 {
64 return tls_common_name(mi->context.c2.tls_multi, false);
65 }
66 else
67 {
68 return "NULL";
69 }
70}
71#endif
72
73#ifdef ENABLE_MANAGEMENT
74static void
75set_cc_config(struct multi_instance *mi, struct buffer_list *cc_config)
76{
78 mi->cc_config = cc_config;
79}
80#endif
81
82static bool
83learn_address_script(const struct multi_context *m, const struct multi_instance *mi, const char *op,
84 const struct mroute_addr *addr)
85{
86 struct gc_arena gc = gc_new();
87 struct env_set *es;
88 bool ret = true;
89 const struct plugin_list *plugins;
90
91 /* get environmental variable source */
92 if (mi && mi->context.c2.es)
93 {
94 es = mi->context.c2.es;
95 }
96 else
97 {
98 es = env_set_create(&gc);
99 }
100
101 /* get plugin source */
102 if (mi)
103 {
104 plugins = mi->context.plugins;
105 }
106 else
107 {
108 plugins = m->top.plugins;
109 }
110
111 if (plugin_defined(plugins, OPENVPN_PLUGIN_LEARN_ADDRESS))
112 {
113 struct argv argv = argv_new();
114 argv_printf(&argv, "%s %s", op, mroute_addr_print(addr, &gc));
115 if (mi)
116 {
118 }
119 if (plugin_call(plugins, OPENVPN_PLUGIN_LEARN_ADDRESS, &argv, NULL, es)
120 != OPENVPN_PLUGIN_FUNC_SUCCESS)
121 {
122 msg(M_WARN, "WARNING: learn-address plugin call failed");
123 ret = false;
124 }
125 argv_free(&argv);
126 }
127
129 {
130 struct argv argv = argv_new();
131 setenv_str(es, "script_type", "learn-address");
133 argv_printf_cat(&argv, "%s %s", op, mroute_addr_print(addr, &gc));
134 if (mi)
135 {
137 }
138 if (!openvpn_run_script(&argv, es, 0, "--learn-address"))
139 {
140 ret = false;
141 }
142 argv_free(&argv);
143 }
144
145 gc_free(&gc);
146 return ret;
147}
148
149void
151{
152 /* write pool data to file */
155 {
157 }
158}
159
160static void
161multi_reap_range(const struct multi_context *m, uint32_t start_bucket, uint32_t end_bucket)
162{
163 struct gc_arena gc = gc_new();
164 struct hash_iterator hi;
165 struct hash_element *he;
166
167 dmsg(D_MULTI_DEBUG, "MULTI: REAP range %d -> %d", start_bucket, end_bucket);
168 hash_iterator_init_range(m->vhash, &hi, start_bucket, end_bucket);
169 while ((he = hash_iterator_next(&hi)) != NULL)
170 {
171 struct multi_route *r = (struct multi_route *)he->value;
172 if (!multi_route_defined(m, r))
173 {
174 dmsg(D_MULTI_DEBUG, "MULTI: REAP DEL %s", mroute_addr_print(&r->addr, &gc));
175 learn_address_script(m, NULL, "delete", &r->addr);
178 }
179 }
181 gc_free(&gc);
182}
183
184static void
186{
188}
189
190static struct multi_reap *
192{
193 struct multi_reap *mr;
194 ALLOC_OBJ(mr, struct multi_reap);
195 mr->bucket_base = 0;
197 mr->last_call = now;
198 return mr;
199}
200
201void
203{
204 struct multi_reap *mr = m->reaper;
205 if (mr->bucket_base >= hash_n_buckets(m->vhash))
206 {
207 mr->bucket_base = 0;
208 }
210 mr->bucket_base += mr->buckets_per_pass;
211 mr->last_call = now;
212}
213
214static void
216{
217 free(mr);
218}
219
220/*
221 * How many buckets in vhash to reap per pass.
222 */
223static uint32_t
224reap_buckets_per_pass(uint32_t n_buckets)
225{
226 return constrain_uint(n_buckets / REAP_DIVISOR, REAP_MIN, REAP_MAX);
227}
228
229#ifdef ENABLE_MANAGEMENT
230
231static uint64_t
232cid_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
233{
234 const unsigned long *k = (const unsigned long *)key;
235 return (uint64_t)*k;
236}
237
238static bool
239cid_compare_function(const void *key1, const void *key2)
240{
241 const unsigned long *k1 = (const unsigned long *)key1;
242 const unsigned long *k2 = (const unsigned long *)key2;
243 return *k1 == *k2;
244}
245
246#endif
247
248#ifdef ENABLE_ASYNC_PUSH
249static uint64_t
250/*
251 * inotify watcher descriptors are used as hash value
252 */
253int_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
254{
255 return (uintptr_t)key;
256}
257
258static bool
259int_compare_function(const void *key1, const void *key2)
260{
261 return (uintptr_t)key1 == (uintptr_t)key2;
262}
263#endif
264
265/*
266 * Main initialization function, init multi_context object.
267 */
268static void
270{
271 struct multi_context *m = t->multi;
272 int dev = DEV_TYPE_UNDEF;
273
274 msg(D_MULTI_LOW, "MULTI: multi_init called, r=%d v=%d", t->options.real_hash_size,
276
277 /*
278 * Get tun/tap/null device type
279 */
281
282 /*
283 * Init our multi_context object.
284 */
285 CLEAR(*m);
286
287 /*
288 * Real address hash table (source port number is
289 * considered to be part of the address). Used
290 * to determine which client sent an incoming packet
291 * which is seen on the TCP/UDP socket.
292 */
295
296 /*
297 * Virtual address hash table. Used to determine
298 * which client to route a packet to.
299 */
302
303#ifdef ENABLE_MANAGEMENT
305#endif
306
307#ifdef ENABLE_ASYNC_PUSH
308 /*
309 * Mapping between inotify watch descriptors and
310 * multi_instances.
311 */
312 m->inotify_watchers =
313 hash_init(t->options.real_hash_size, int_hash_function, int_compare_function);
314#endif
315
316 /*
317 * This is our scheduler, for time-based wakeup
318 * events.
319 */
320 m->schedule = schedule_init();
321
322 /*
323 * Limit frequency of incoming connections to control
324 * DoS.
325 */
329
330 /*
331 * Allocate broadcast/multicast buffer list
332 */
334
335 /*
336 * Different status file format options are available
337 */
339
340 /*
341 * Possibly allocate an ifconfig pool, do it
342 * differently based on whether a tun or tap style
343 * tunnel.
344 */
346 {
348
349 if (dev == DEV_TYPE_TUN && t->options.topology == TOP_NET30)
350 {
352 }
353
359
360 /* reload pool data from file */
362 {
364 }
365 }
366
367 /*
368 * Help us keep track of routing table.
369 */
371
372 /*
373 * Initialize route and instance reaper.
374 */
376
377 /*
378 * Get local ifconfig address
379 */
380 CLEAR(m->local);
381 ASSERT(t->c1.tuntap);
383
384 /*
385 * Per-client limits
386 */
388
389 m->instances = calloc(m->max_clients, sizeof(struct multi_instance *));
390
391 m->top.c2.event_set = t->c2.event_set;
392
393 /*
394 * Initialize multi-socket I/O wait object
395 */
398
399 /*
400 * Allow client <-> client communication, without going through
401 * tun/tap interface and network stack?
402 */
404
405 /* initialize stale routes check timer */
407 {
408 msg(M_INFO,
409 "Initializing stale route check timer to run every %i seconds and to removing routes with activity timeout older than %i seconds",
412 }
413
415}
416
417const char *
418multi_instance_string(const struct multi_instance *mi, bool null, struct gc_arena *gc)
419{
420 if (mi)
421 {
423 const char *cn = tls_common_name(mi->context.c2.tls_multi, true);
424
425 if (cn)
426 {
427 buf_printf(&out, "%s/", cn);
428 }
429 buf_printf(&out, "%s", mroute_addr_print(&mi->real, gc));
431 && dco_enabled(&mi->context.options))
432 {
433 buf_printf(&out, " rx-peer-id=%d", mi->context.c2.tls_multi->rx_peer_id);
434 }
435 return BSTR(&out);
436 }
437 else if (null)
438 {
439 return NULL;
440 }
441 else
442 {
443 return "UNDEF";
444 }
445}
446
447static void
449{
450 struct gc_arena gc = gc_new();
451 const char *prefix = multi_instance_string(mi, true, &gc);
452 if (prefix)
453 {
454 strncpynt(mi->msg_prefix, prefix, sizeof(mi->msg_prefix));
455 }
456 else
457 {
458 mi->msg_prefix[0] = '\0';
459 }
460 set_prefix(mi);
461 gc_free(&gc);
462}
463
464void
466{
467 mi->msg_prefix[0] = '\0';
468 set_prefix(mi);
469}
470
471/*
472 * Tell the route helper about deleted iroutes so
473 * that it can update its mask of currently used
474 * CIDR netlengths.
475 */
476static void
478{
479 const struct iroute *ir;
480 const struct iroute_ipv6 *ir6;
481
482 /* check if DCO iroutes were already removed when scheduling a delayed exit */
483 if (mi->context.did_dco_iroutes)
484 {
485 mi->context.did_dco_iroutes = false;
487 }
488
490 {
491 for (ir = mi->context.options.iroutes; ir != NULL; ir = ir->next)
492 {
494 }
495
496 for (ir6 = mi->context.options.iroutes_ipv6; ir6 != NULL; ir6 = ir6->next)
497 {
499 }
500 }
501}
502
503static void
505{
506 setenv_counter(c->c2.es, "bytes_received", c->c2.link_read_bytes + c->c2.dco_read_bytes);
507 setenv_counter(c->c2.es, "bytes_sent", c->c2.link_write_bytes + c->c2.dco_write_bytes);
508}
509
510static void
512{
513 /* setenv client real IP address */
515
516 /* setenv stats */
517 setenv_stats(&mi->context);
518
519 /* setenv connection duration */
520 setenv_long_long(mi->context.c2.es, "time_duration", now - mi->created);
521}
522
523static void
525{
527
528 if (plugin_defined(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_DISCONNECT))
529 {
530 if (plugin_call(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_DISCONNECT, NULL, NULL,
531 mi->context.c2.es)
532 != OPENVPN_PLUGIN_FUNC_SUCCESS)
533 {
534 msg(M_WARN, "WARNING: client-disconnect plugin call failed");
535 }
536 }
537
539 {
540 struct argv argv = argv_new();
541 setenv_str(mi->context.c2.es, "script_type", "client-disconnect");
543 openvpn_run_script(&argv, mi->context.c2.es, 0, "--client-disconnect");
544 argv_free(&argv);
545 }
546#ifdef ENABLE_MANAGEMENT
547 if (management)
548 {
550 }
551#endif
552}
553
554void
555multi_close_instance(struct multi_context *m, struct multi_instance *mi, bool shutdown)
556{
557 ASSERT(!mi->halt);
558 mi->halt = true;
559 bool is_dgram = proto_is_dgram(mi->context.c2.link_sockets[0]->info.proto);
560
561 dmsg(D_MULTI_DEBUG, "MULTI: multi_close_instance called");
562
563 /* adjust current client connection count */
564 m->n_clients += mi->n_clients_delta;
565 mi->n_clients_delta = 0;
566
567 /* prevent dangling pointers */
568 if (m->pending == mi)
569 {
570 multi_set_pending(m, NULL);
571 }
572 if (m->earliest_wakeup == mi)
573 {
574 m->earliest_wakeup = NULL;
575 }
576
577 if (!shutdown)
578 {
579 if (mi->did_real_hash)
580 {
581 ASSERT(hash_remove(m->hash, &mi->real));
582 }
583#ifdef ENABLE_MANAGEMENT
584 if (mi->did_cid_hash)
585 {
587 }
588#endif
589
590#ifdef ENABLE_ASYNC_PUSH
591 if (mi->inotify_watch != -1)
592 {
593 hash_remove(m->inotify_watchers, (void *)(uintptr_t)mi->inotify_watch);
594 mi->inotify_watch = -1;
595 }
596#endif
597
599 {
600 m->instances[mi->context.c2.tls_multi->rx_peer_id] = NULL;
601
602 /* Adjust the max_peerid as this might have been the highest
603 * peer id instance */
604 while (m->max_peerid > 0 && m->instances[m->max_peerid] == NULL)
605 {
606 m->max_peerid--;
607 }
608 }
609
611
612 ifconfig_pool_release(m->ifconfig_pool, mi->vaddr_handle, false);
613
614 if (mi->did_iroutes)
615 {
616 multi_del_iroutes(m, mi);
617 mi->did_iroutes = false;
618 }
619
620 if (!is_dgram)
621 {
623 }
624
626 }
627
628#ifdef ENABLE_MANAGEMENT
629 set_cc_config(mi, NULL);
630#endif
631
633 {
635 }
636
638
640
642
643 /*
644 * Don't actually delete the instance memory allocation yet,
645 * because virtual routes may still point to it. Let the
646 * vhash reaper deal with it.
647 */
649}
650
651/*
652 * Called on shutdown or restart.
653 */
654static void
656{
657 if (m->hash)
658 {
659 /* fetch final stats while all peers can still be mapped to their instances */
660 if (dco_enabled(&m->top.options))
661 {
663 }
664
665 for (uint32_t i = 0; i <= m->max_peerid; i++)
666 {
667 struct multi_instance *mi = m->instances[i];
668 if (mi)
669 {
670 multi_close_instance(m, mi, true);
671 }
672 }
673
675
676 hash_free(m->hash);
677 hash_free(m->vhash);
678#ifdef ENABLE_MANAGEMENT
680#endif
681 m->hash = NULL;
682
683 free(m->instances);
684
685#ifdef ENABLE_ASYNC_PUSH
686 hash_free(m->inotify_watchers);
687 m->inotify_watchers = NULL;
688#endif
689
691 mbuf_free(m->mbuf);
698 }
699}
700
701/*
702 * Create a client instance object for a newly connected client.
703 */
704struct multi_instance *
706 struct link_socket *sock)
707{
708 struct gc_arena gc = gc_new();
709 struct multi_instance *mi;
710
711 msg(D_MULTI_MEDIUM, "MULTI: multi_create_instance called");
712
714
715 mi->gc = gc_new();
717 mi->vaddr_handle = -1;
718 mi->created = now;
720
721 if (real)
722 {
723 mi->real = *real;
724 generate_prefix(mi);
725 }
726
727 inherit_context_child(&mi->context, &m->top, sock);
728 if (IS_SIG(&mi->context))
729 {
730 goto err;
731 }
732
734
735 if (hash_n_elements(m->hash) >= m->max_clients)
736 {
738 "MULTI: new incoming connection would exceed maximum number of clients (%d)",
739 m->max_clients);
740 goto err;
741 }
742
743 if (!real) /* TCP mode? */
744 {
746 {
747 goto err;
748 }
749 generate_prefix(mi);
750 }
751
752#ifdef ENABLE_MANAGEMENT
753 do
754 {
756 } while (!hash_add(m->cid_hash, &mi->context.c2.mda_context.cid, mi, false));
757 mi->did_cid_hash = true;
758#endif
759
760 mi->context.c2.push_request_received = false;
761#ifdef ENABLE_ASYNC_PUSH
762 mi->inotify_watch = -1;
763#endif
764
766 {
767 msg(D_MULTI_ERRORS, "MULTI: signal occurred during client instance initialization");
768 goto err;
769 }
770
772 mi->ev_arg.u.mi = mi;
773
774 gc_free(&gc);
775 return mi;
776
777err:
778 multi_close_instance(m, mi, false);
779 gc_free(&gc);
780 return NULL;
781}
782
783/*
784 * Dump tables -- triggered by SIGUSR2.
785 * If status file is defined, write to file.
786 * If status file is NULL, write to syslog.
787 */
788static void
789multi_print_status(struct multi_context *m, struct status_output *so, const int version)
790{
791 if (m->hash)
792 {
793 struct gc_arena gc_top = gc_new();
794 struct hash_iterator hi;
795 const struct hash_element *he;
796
797 status_reset(so);
798
799 if (dco_enabled(&m->top.options))
800 {
801 if (dco_get_peer_stats_multi(&m->top.c1.tuntap->dco, true) < 0)
802 {
803 return;
804 }
805 }
806
807 if (version == 1)
808 {
809 /*
810 * Status file version 1
811 */
812 status_printf(so, "OpenVPN CLIENT LIST");
813 status_printf(so, "Updated,%s", time_string(0, 0, false, &gc_top));
814 status_printf(so, "Common Name,Real Address,Bytes Received,Bytes Sent,Connected Since");
815 hash_iterator_init(m->hash, &hi);
816 while ((he = hash_iterator_next(&hi)))
817 {
818 struct gc_arena gc = gc_new();
819 const struct multi_instance *mi = (struct multi_instance *)he->value;
820
821 if (!mi->halt)
822 {
823 status_printf(so, "%s,%s," counter_format "," counter_format ",%s",
825 mroute_addr_print(&mi->real, &gc),
828 time_string(mi->created, 0, false, &gc));
829 }
830 gc_free(&gc);
831 }
833
834 status_printf(so, "ROUTING TABLE");
835 status_printf(so, "Virtual Address,Common Name,Real Address,Last Ref");
836 hash_iterator_init(m->vhash, &hi);
837 while ((he = hash_iterator_next(&hi)))
838 {
839 struct gc_arena gc = gc_new();
840 const struct multi_route *route = (struct multi_route *)he->value;
841
843 {
844 const struct multi_instance *mi = route->instance;
845 const struct mroute_addr *ma = &route->addr;
846 char flags[2] = { 0, 0 };
847
848 if (route->flags & MULTI_ROUTE_CACHE)
849 {
850 flags[0] = 'C';
851 }
852 status_printf(so, "%s%s,%s,%s,%s", mroute_addr_print(ma, &gc), flags,
854 mroute_addr_print(&mi->real, &gc),
855 time_string(route->last_reference, 0, false, &gc));
856 }
857 gc_free(&gc);
858 }
860
861 status_printf(so, "GLOBAL STATS");
862 if (m->mbuf)
863 {
864 status_printf(so, "Max bcast/mcast queue length,%d", mbuf_maximum_queued(m->mbuf));
865 }
866
867 status_printf(so, "END");
868 }
869 else if (version == 2 || version == 3)
870 {
871 const char sep = (version == 3) ? '\t' : ',';
872
873 /*
874 * Status file version 2 and 3
875 */
876 status_printf(so, "TITLE%c%s", sep, title_string);
877 status_printf(so, "TIME%c%s%c%u", sep, time_string(now, 0, false, &gc_top), sep,
878 (unsigned int)now);
880 so,
881 "HEADER%cCLIENT_LIST%cCommon Name%cReal Address%cVirtual Address%cVirtual IPv6 Address%cBytes Received%cBytes Sent%cConnected Since%cConnected Since (time_t)%cUsername%cClient ID%cPeer ID%cData Channel Cipher",
882 sep, sep, sep, sep, sep, sep, sep, sep, sep, sep, sep, sep, sep);
883 hash_iterator_init(m->hash, &hi);
884 while ((he = hash_iterator_next(&hi)))
885 {
886 struct gc_arena gc = gc_new();
887 const struct multi_instance *mi = (struct multi_instance *)he->value;
888
889 if (!mi->halt)
890 {
892 so,
893 "CLIENT_LIST%c%s%c%s%c%s%c%s%c" counter_format "%c" counter_format
894 "%c%s%c%u%c%s%c"
895#ifdef ENABLE_MANAGEMENT
896 "%lu"
897#else
898 ""
899#endif
900 "%c%" PRIu32 "%c%s",
901 sep, tls_common_name(mi->context.c2.tls_multi, false), sep,
902 mroute_addr_print(&mi->real, &gc), sep,
907 time_string(mi->created, 0, false, &gc), sep, (unsigned int)mi->created,
908 sep, tls_username(mi->context.c2.tls_multi, false),
909#ifdef ENABLE_MANAGEMENT
910 sep, mi->context.c2.mda_context.cid,
911#else
912 sep,
913#endif
916 }
917 gc_free(&gc);
918 }
920
922 so,
923 "HEADER%cROUTING_TABLE%cVirtual Address%cCommon Name%cReal Address%cLast Ref%cLast Ref (time_t)",
924 sep, sep, sep, sep, sep, sep);
925 hash_iterator_init(m->vhash, &hi);
926 while ((he = hash_iterator_next(&hi)))
927 {
928 struct gc_arena gc = gc_new();
929 const struct multi_route *route = (struct multi_route *)he->value;
930
932 {
933 const struct multi_instance *mi = route->instance;
934 const struct mroute_addr *ma = &route->addr;
935 char flags[2] = { 0, 0 };
936
937 if (route->flags & MULTI_ROUTE_CACHE)
938 {
939 flags[0] = 'C';
940 }
941 status_printf(so, "ROUTING_TABLE%c%s%s%c%s%c%s%c%s%c%u", sep,
942 mroute_addr_print(ma, &gc), flags, sep,
943 tls_common_name(mi->context.c2.tls_multi, false), sep,
944 mroute_addr_print(&mi->real, &gc), sep,
945 time_string(route->last_reference, 0, false, &gc), sep,
946 (unsigned int)route->last_reference);
947 }
948 gc_free(&gc);
949 }
951
952 if (m->mbuf)
953 {
954 status_printf(so, "GLOBAL_STATS%cMax bcast/mcast queue length%c%d", sep, sep,
956 }
957
958 status_printf(so, "GLOBAL_STATS%cdco_enabled%c%d", sep, sep,
959 dco_enabled(&m->top.options));
960 status_printf(so, "END");
961 }
962 else
963 {
964 status_printf(so, "ERROR: bad status format version number");
965 }
966
967#ifdef PACKET_TRUNCATION_CHECK
968 {
969 status_printf(so, "HEADER,ERRORS,Common Name,TUN Read Trunc,TUN Write Trunc,Pre-encrypt Trunc,Post-decrypt Trunc");
970 hash_iterator_init(m->hash, &hi);
971 while ((he = hash_iterator_next(&hi)))
972 {
973 struct gc_arena gc = gc_new();
974 const struct multi_instance *mi = (struct multi_instance *)he->value;
975
976 if (!mi->halt)
977 {
978 status_printf(so,
979 "ERRORS,%s," counter_format "," counter_format "," counter_format
980 "," counter_format,
982 m->top.c2.n_trunc_tun_read, mi->context.c2.n_trunc_tun_write,
983 mi->context.c2.n_trunc_pre_encrypt,
984 mi->context.c2.n_trunc_post_decrypt);
985 }
986 gc_free(&gc);
987 }
989 }
990#endif /* ifdef PACKET_TRUNCATION_CHECK */
991
992 status_flush(so);
993 gc_free(&gc_top);
994 }
995
996#ifdef ENABLE_ASYNC_PUSH
997 if (m->inotify_watchers)
998 {
999 msg(D_MULTI_DEBUG, "inotify watchers count: %d", hash_n_elements(m->inotify_watchers));
1000 }
1001#endif
1002}
1003
1004/*
1005 * Learn a virtual address or route.
1006 * The learn will fail if the learn address
1007 * script/plugin fails. In this case the
1008 * return value may be != mi.
1009 * Return the instance which owns this route,
1010 * or NULL if none.
1011 */
1012static struct multi_instance *
1013multi_learn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr,
1014 const unsigned int flags)
1015{
1016 struct hash_element *he;
1017 const uint64_t hv = hash_value(m->vhash, addr);
1018 struct hash_bucket *bucket = hash_bucket(m->vhash, hv);
1019 struct multi_route *oldroute = NULL;
1020 struct multi_instance *owner = NULL;
1021 struct gc_arena gc = gc_new();
1022
1023 /* if route currently exists, get the instance which owns it */
1024 he = hash_lookup_fast(m->vhash, bucket, addr, hv);
1025 if (he)
1026 {
1027 oldroute = (struct multi_route *)he->value;
1028 }
1029 if (oldroute && multi_route_defined(m, oldroute))
1030 {
1031 owner = oldroute->instance;
1032 }
1033
1034 /* do we need to add address to hash table? */
1035 if ((!owner || owner != mi) && mroute_learnable_address(addr, &gc)
1036 && !mroute_addr_equal(addr, &m->local))
1037 {
1038 struct multi_route *newroute;
1039 bool learn_succeeded = false;
1040
1041 ALLOC_OBJ(newroute, struct multi_route);
1042 newroute->addr = *addr;
1043 newroute->instance = mi;
1044 newroute->flags = flags;
1045 newroute->last_reference = now;
1046 newroute->cache_generation = 0;
1047
1048 /* The cache is invalidated when cache_generation is incremented */
1050 {
1052 }
1053
1054 if (oldroute) /* route already exists? */
1055 {
1056 if (route_quota_test(mi) && learn_address_script(m, mi, "update", &newroute->addr))
1057 {
1058 learn_succeeded = true;
1059 owner = mi;
1061 route_quota_inc(mi);
1062
1063 /* delete old route */
1064 multi_route_del(oldroute);
1065
1066 /* modify hash table entry, replacing old route */
1067 he->key = &newroute->addr;
1068 he->value = newroute;
1069 }
1070 }
1071 else
1072 {
1073 if (route_quota_test(mi) && learn_address_script(m, mi, "add", &newroute->addr))
1074 {
1075 learn_succeeded = true;
1076 owner = mi;
1078 route_quota_inc(mi);
1079
1080 /* add new route */
1081 hash_add_fast(m->vhash, bucket, &newroute->addr, hv, newroute);
1082 }
1083 }
1084
1085 msg(D_MULTI_LOW, "MULTI: Learn%s: %s -> %s", learn_succeeded ? "" : " FAILED",
1086 mroute_addr_print(&newroute->addr, &gc), multi_instance_string(mi, false, &gc));
1087
1088 if (!learn_succeeded)
1089 {
1090 free(newroute);
1091 }
1092 }
1093 gc_free(&gc);
1094
1095 return owner;
1096}
1097
1098/*
1099 * Get client instance based on virtual address.
1100 */
1101static struct multi_instance *
1103 bool cidr_routing)
1104{
1105 struct multi_route *route;
1106 struct multi_instance *ret = NULL;
1107
1108 /* check for local address */
1109 if (mroute_addr_equal(addr, &m->local))
1110 {
1111 return NULL;
1112 }
1113
1114 route = (struct multi_route *)hash_lookup(m->vhash, addr);
1115
1116 /* does host route (possible cached) exist? */
1117 if (route && multi_route_defined(m, route))
1118 {
1119 struct multi_instance *mi = route->instance;
1120 route->last_reference = now;
1121 ret = mi;
1122 }
1123 else if (cidr_routing) /* do we need to regenerate a host route cache entry? */
1124 {
1125 struct mroute_helper *rh = m->route_helper;
1126 struct mroute_addr tryaddr;
1127 int i;
1128
1129 /* cycle through each CIDR length */
1130 for (i = 0; i < rh->n_net_len; ++i)
1131 {
1132 tryaddr = *addr;
1133 tryaddr.type |= MR_WITH_NETBITS;
1134 tryaddr.netbits = rh->net_len[i];
1136
1137 /* look up a possible route with netbits netmask */
1138 route = (struct multi_route *)hash_lookup(m->vhash, &tryaddr);
1139
1140 if (route && multi_route_defined(m, route))
1141 {
1142 /* found an applicable route, cache host route */
1143 struct multi_instance *mi = route->instance;
1145 ret = mi;
1146 break;
1147 }
1148 }
1149 }
1150
1151#ifndef ENABLE_SMALL
1153 {
1154 struct gc_arena gc = gc_new();
1155 const char *addr_text = mroute_addr_print(addr, &gc);
1156 if (ret)
1157 {
1158 dmsg(D_MULTI_DEBUG, "GET INST BY VIRT: %s -> %s via %s", addr_text,
1159 multi_instance_string(ret, false, &gc), mroute_addr_print(&route->addr, &gc));
1160 }
1161 else
1162 {
1163 dmsg(D_MULTI_DEBUG, "GET INST BY VIRT: %s [failed]", addr_text);
1164 }
1165 gc_free(&gc);
1166 }
1167#endif
1168
1169 ASSERT(!(ret && ret->halt));
1170 return ret;
1171}
1172
1173/*
1174 * Helper function to multi_learn_addr().
1175 */
1176static struct multi_instance *
1178 int netbits, /* -1 if host route, otherwise # of network bits in address */
1179 bool primary)
1180{
1181 struct openvpn_sockaddr remote_si;
1182 struct mroute_addr addr = { 0 };
1183
1184 CLEAR(remote_si);
1185 remote_si.addr.in4.sin_family = AF_INET;
1186 remote_si.addr.in4.sin_addr.s_addr = htonl(a);
1187 addr.proto = 0;
1188 ASSERT(mroute_extract_openvpn_sockaddr(&addr, &remote_si, false));
1189
1190 if (netbits >= 0)
1191 {
1192 addr.type |= MR_WITH_NETBITS;
1193 addr.netbits = (uint8_t)netbits;
1194 }
1195
1196 struct multi_instance *owner = multi_learn_addr(m, mi, &addr, MULTI_ROUTE_PERMANENT);
1197#ifdef ENABLE_MANAGEMENT
1198 if (management && owner)
1199 {
1200 management_learn_addr(&mi->context.c2.mda_context, &addr, primary);
1201 }
1202#endif
1203 if (primary && multi_check_push_ifconfig_extra_route(&mi->context.options, addr.v4.addr))
1204 {
1205 /* "primary" is the VPN ifconfig address of the peer */
1206 /* if it does not fall into the network defined by ifconfig_local
1207 * we install this as extra onscope address on the interface */
1208 addr.netbits = 32;
1209 addr.type |= MR_ONLINK_DCO_ADDR;
1210
1211 dco_install_iroute(m, mi, &addr);
1212 }
1213 else if (!primary)
1214 {
1215 ASSERT(netbits >= 0); /* DCO requires populated netbits */
1216 dco_install_iroute(m, mi, &addr);
1217 }
1218
1219 return owner;
1220}
1221
1222static struct multi_instance *
1223multi_learn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6,
1224 int netbits, /* -1 if host route, otherwise # of network bits in address */
1225 bool primary)
1226{
1227 struct mroute_addr addr = { 0 };
1228
1229 addr.len = 16;
1230 addr.type = MR_ADDR_IPV6;
1231 addr.netbits = 0;
1232 addr.v6.addr = a6;
1233
1234 if (netbits >= 0)
1235 {
1236 addr.type |= MR_WITH_NETBITS;
1237 addr.netbits = (uint8_t)netbits;
1239 }
1240
1241 struct multi_instance *owner = multi_learn_addr(m, mi, &addr, MULTI_ROUTE_PERMANENT);
1242#ifdef ENABLE_MANAGEMENT
1243 if (management && owner)
1244 {
1245 management_learn_addr(&mi->context.c2.mda_context, &addr, primary);
1246 }
1247#endif
1249 {
1250 /* "primary" is the VPN ifconfig address of the peer */
1251 /* if it does not fall into the network defined by ifconfig_local
1252 * we install this as extra onscope address on the interface */
1253 addr.netbits = 128;
1254 addr.type |= MR_ONLINK_DCO_ADDR;
1255
1256 dco_install_iroute(m, mi, &addr);
1257 }
1258 else if (!primary)
1259 {
1260 /* "primary" is the VPN ifconfig address of the peer and already
1261 * known to DCO, so only install "extra" iroutes (primary = false)
1262 */
1263 ASSERT(netbits >= 0); /* DCO requires populated netbits */
1264 dco_install_iroute(m, mi, &addr);
1265 }
1266
1267 return owner;
1268}
1269
1270/*
1271 * A new client has connected, add routes (server -> client)
1272 * to internal routing table.
1273 */
1274static void
1276{
1277 struct gc_arena gc = gc_new();
1278 const struct iroute *ir;
1279 const struct iroute_ipv6 *ir6;
1281 {
1282 mi->did_iroutes = true;
1283 /* multi_learn_in{6}_addr_t takes care of installing the DCO iroute */
1284 mi->context.did_dco_iroutes = true;
1285 for (ir = mi->context.options.iroutes; ir != NULL; ir = ir->next)
1286 {
1287 if (ir->netbits >= 0)
1288 {
1289 msg(D_MULTI_LOW, "MULTI: internal route %s/%d -> %s",
1290 print_in_addr_t(ir->network, 0, &gc), ir->netbits,
1291 multi_instance_string(mi, false, &gc));
1292 }
1293 else
1294 {
1295 msg(D_MULTI_LOW, "MULTI: internal route %s -> %s",
1296 print_in_addr_t(ir->network, 0, &gc), multi_instance_string(mi, false, &gc));
1297 }
1298
1300
1301 multi_learn_in_addr_t(m, mi, ir->network, ir->netbits, false);
1302 }
1303 for (ir6 = mi->context.options.iroutes_ipv6; ir6 != NULL; ir6 = ir6->next)
1304 {
1305 msg(D_MULTI_LOW, "MULTI: internal route %s/%d -> %s",
1306 print_in6_addr(ir6->network, 0, &gc), ir6->netbits,
1307 multi_instance_string(mi, false, &gc));
1308
1310
1311 multi_learn_in6_addr(m, mi, ir6->network, ir6->netbits, false);
1312 }
1313 }
1314 gc_free(&gc);
1315}
1316
1317/*
1318 * Given an instance (new_mi), delete all other instances which use the
1319 * same common name.
1320 */
1321static void
1323{
1324 if (new_mi)
1325 {
1326 const char *new_cn = tls_common_name(new_mi->context.c2.tls_multi, true);
1327 if (new_cn)
1328 {
1329 int count = 0;
1330
1331 for (uint32_t i = 0; i <= m->max_peerid; i++)
1332 {
1333 struct multi_instance *mi = m->instances[i];
1334 if (mi && mi != new_mi && !mi->halt)
1335 {
1336 const char *cn = tls_common_name(mi->context.c2.tls_multi, true);
1337 if (cn && !strcmp(cn, new_cn))
1338 {
1339 multi_close_instance(m, mi, false);
1340 ++count;
1341 }
1342 }
1343 }
1344
1345 if (count)
1346 {
1348 "MULTI: new connection by client '%s' will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.",
1349 new_cn);
1350 }
1351 }
1352 }
1353}
1354
1355static void
1357{
1358 struct gc_arena gc = gc_new();
1359 struct hash_iterator hi;
1360 struct hash_element *he;
1361
1362 dmsg(D_MULTI_DEBUG, "MULTI: Checking stale routes");
1364 while ((he = hash_iterator_next(&hi)) != NULL)
1365 {
1366 struct multi_route *r = (struct multi_route *)he->value;
1368 && difftime(now, r->last_reference) >= m->top.options.stale_routes_ageing_time)
1369 {
1370 dmsg(D_MULTI_DEBUG, "MULTI: Deleting stale route for address '%s'",
1371 mroute_addr_print(&r->addr, &gc));
1372 learn_address_script(m, NULL, "delete", &r->addr);
1373 multi_route_del(r);
1375 }
1376 }
1377 hash_iterator_free(&hi);
1378 gc_free(&gc);
1379}
1380
1381/*
1382 * Ensure that endpoint to be pushed to client
1383 * complies with --ifconfig-push-constraint directive.
1384 */
1385static bool
1387{
1388 const struct options *o = &c->options;
1390 {
1393 }
1394 else
1395 {
1396 return true;
1397 }
1398}
1399
1400/*
1401 * Select a virtual address for a new client instance.
1402 * Use an --ifconfig-push directive, if given (static IP).
1403 * Otherwise use an --ifconfig-pool address (dynamic IP).
1404 */
1405static void
1407{
1408 struct gc_arena gc = gc_new();
1409
1410 /*
1411 * If ifconfig addresses were set by dynamic config file,
1412 * release pool addresses, otherwise keep them.
1413 */
1415 {
1416 /* ifconfig addresses were set statically,
1417 * release dynamic allocation */
1418 if (mi->vaddr_handle >= 0)
1419 {
1421 mi->vaddr_handle = -1;
1422 }
1423
1424 mi->context.c2.push_ifconfig_defined = true;
1429
1430 /* the current implementation does not allow "static IPv4, pool IPv6",
1431 * (see below) so issue a warning if that happens - don't break the
1432 * session, though, as we don't even know if this client WANTS IPv6
1433 */
1436 {
1437 msg(M_INFO,
1438 "MULTI_sva: WARNING: if --ifconfig-push is used for IPv4, automatic IPv6 assignment from --ifconfig-ipv6-pool does not work. Use --ifconfig-ipv6-push for IPv6 then.");
1439 }
1440 }
1441 else if (m->ifconfig_pool && mi->vaddr_handle < 0) /* otherwise, choose a pool address */
1442 {
1443 in_addr_t local = 0, remote = 0;
1444 struct in6_addr remote_ipv6;
1445 const char *cn = NULL;
1446
1447 if (!mi->context.options.duplicate_cn)
1448 {
1449 cn = tls_common_name(mi->context.c2.tls_multi, true);
1450 }
1451
1452 CLEAR(remote_ipv6);
1453 mi->vaddr_handle =
1454 ifconfig_pool_acquire(m->ifconfig_pool, &local, &remote, &remote_ipv6, cn);
1455 if (mi->vaddr_handle >= 0)
1456 {
1457 const int tunnel_type = TUNNEL_TYPE(mi->context.c1.tuntap);
1458 const int tunnel_topology = TUNNEL_TOPOLOGY(mi->context.c1.tuntap);
1459
1460 msg(M_INFO, "MULTI_sva: pool returned IPv4=%s, IPv6=%s",
1462 : "(Not enabled)"),
1464 ? print_in6_addr(remote_ipv6, 0, &gc)
1465 : "(Not enabled)"));
1466
1468 {
1469 /* set push_ifconfig_remote_netmask from pool ifconfig address(es) */
1470 mi->context.c2.push_ifconfig_local = remote;
1471 if (tunnel_type == DEV_TYPE_TAP
1472 || (tunnel_type == DEV_TYPE_TUN && tunnel_topology == TOP_SUBNET))
1473 {
1477 {
1480 }
1481 }
1482 else if (tunnel_type == DEV_TYPE_TUN)
1483 {
1484 if (tunnel_topology == TOP_P2P)
1485 {
1487 }
1488 else if (tunnel_topology == TOP_NET30)
1489 {
1491 }
1492 }
1493
1495 {
1496 mi->context.c2.push_ifconfig_defined = true;
1497 }
1498 else
1499 {
1501 "MULTI: no --ifconfig-pool netmask parameter is available to push to %s",
1502 multi_instance_string(mi, false, &gc));
1503 }
1504 }
1505
1507 {
1508 mi->context.c2.push_ifconfig_ipv6_local = remote_ipv6;
1513 }
1514 }
1515 else
1516 {
1517 msg(D_MULTI_ERRORS, "MULTI: no free --ifconfig-pool addresses are available");
1518 }
1519 }
1520
1521 /* IPv6 push_ifconfig is a bit problematic - since IPv6 shares the
1522 * pool handling with IPv4, the combination "static IPv4, dynamic IPv6"
1523 * will fail (because no pool will be allocated in this case).
1524 * OTOH, this doesn't make too much sense in reality - and the other
1525 * way round ("dynamic IPv4, static IPv6") or "both static" makes sense
1526 * -> and so it's implemented right now
1527 */
1529 {
1534
1535 msg(M_INFO, "MULTI_sva: push_ifconfig_ipv6 %s/%d",
1538 }
1539
1540 gc_free(&gc);
1541}
1542
1543/*
1544 * Set virtual address environmental variables.
1545 */
1546static void
1548{
1549 setenv_del(mi->context.c2.es, "ifconfig_pool_local_ip");
1550 setenv_del(mi->context.c2.es, "ifconfig_pool_remote_ip");
1551 setenv_del(mi->context.c2.es, "ifconfig_pool_netmask");
1552
1554 {
1555 const int tunnel_type = TUNNEL_TYPE(mi->context.c1.tuntap);
1556 const int tunnel_topology = TUNNEL_TOPOLOGY(mi->context.c1.tuntap);
1557
1558 setenv_in_addr_t(mi->context.c2.es, "ifconfig_pool_remote_ip",
1560
1561 if (tunnel_type == DEV_TYPE_TAP
1562 || (tunnel_type == DEV_TYPE_TUN && tunnel_topology == TOP_SUBNET))
1563 {
1564 setenv_in_addr_t(mi->context.c2.es, "ifconfig_pool_netmask",
1566 }
1567 else if (tunnel_type == DEV_TYPE_TUN)
1568 {
1569 setenv_in_addr_t(mi->context.c2.es, "ifconfig_pool_local_ip",
1571 }
1572 }
1573
1574 setenv_del(mi->context.c2.es, "ifconfig_pool_local_ip6");
1575 setenv_del(mi->context.c2.es, "ifconfig_pool_remote_ip6");
1576 setenv_del(mi->context.c2.es, "ifconfig_pool_ip6_netbits");
1577
1579 {
1580 setenv_in6_addr(mi->context.c2.es, "ifconfig_pool_remote",
1582 setenv_in6_addr(mi->context.c2.es, "ifconfig_pool_local",
1584 setenv_int(mi->context.c2.es, "ifconfig_pool_ip6_netbits",
1586 }
1587}
1588
1589/*
1590 * Called after client-connect script is called
1591 */
1592static void
1593multi_client_connect_post(struct multi_context *m, struct multi_instance *mi, const char *dc_file,
1594 uint64_t *option_types_found)
1595{
1596 /* Did script generate a dynamic config file? */
1597 if (platform_test_file(dc_file))
1598 {
1600 CLIENT_CONNECT_OPT_MASK, option_types_found, mi->context.c2.es);
1601
1602 /*
1603 * If the --client-connect script generates a config file
1604 * with an --ifconfig-push directive, it will override any
1605 * --ifconfig-push directive from the --client-config-dir
1606 * directory or any --ifconfig-pool dynamic address.
1607 */
1610 }
1611}
1612
1613#ifdef ENABLE_PLUGIN
1614
1615/*
1616 * Called after client-connect plug-in is called
1617 */
1618static void
1620 const struct plugin_return *pr, uint64_t *option_types_found)
1621{
1622 struct plugin_return config;
1623
1624 plugin_return_get_column(pr, &config, "config");
1625
1626 /* Did script generate a dynamic config file? */
1627 if (plugin_return_defined(&config))
1628 {
1629 int i;
1630 for (i = 0; i < config.n; ++i)
1631 {
1632 if (config.list[i] && config.list[i]->value)
1633 {
1634 options_string_import(&mi->context.options, config.list[i]->value,
1636 option_types_found, mi->context.c2.es);
1637 }
1638 }
1639
1640 /*
1641 * If the --client-connect script generates a config file
1642 * with an --ifconfig-push directive, it will override any
1643 * --ifconfig-push directive from the --client-config-dir
1644 * directory or any --ifconfig-pool dynamic address.
1645 */
1648 }
1649}
1650
1651#endif /* ifdef ENABLE_PLUGIN */
1652
1653
1654/*
1655 * Called to load management-derived client-connect config
1656 */
1658multi_client_connect_mda(struct multi_context *m, struct multi_instance *mi, bool deferred,
1659 uint64_t *option_types_found)
1660{
1661 /* We never return CC_RET_DEFERRED */
1662 ASSERT(!deferred);
1664#ifdef ENABLE_MANAGEMENT
1665 if (mi->cc_config)
1666 {
1667 struct buffer_entry *be;
1668 for (be = mi->cc_config->head; be != NULL; be = be->next)
1669 {
1670 const char *opt = BSTR(&be->buf);
1672 CLIENT_CONNECT_OPT_MASK, option_types_found, mi->context.c2.es);
1673 }
1674
1675 /*
1676 * If the --client-connect script generates a config file
1677 * with an --ifconfig-push directive, it will override any
1678 * --ifconfig-push directive from the --client-config-dir
1679 * directory or any --ifconfig-pool dynamic address.
1680 */
1683
1684 ret = CC_RET_SUCCEEDED;
1685 }
1686#endif /* ifdef ENABLE_MANAGEMENT */
1687 return ret;
1688}
1689
1690static void
1692{
1693 struct gc_arena gc = gc_new();
1694
1695 /* setenv incoming cert common name for script */
1696 setenv_str(mi->context.c2.es, "common_name", tls_common_name(mi->context.c2.tls_multi, true));
1697
1698 /* setenv client real IP address */
1700
1701 /* setenv client virtual IP address */
1703
1704 /* setenv connection time */
1705 {
1706 const char *created_ascii = time_string(mi->created, 0, false, &gc);
1707 setenv_str(mi->context.c2.es, "time_ascii", created_ascii);
1708 setenv_long_long(mi->context.c2.es, "time_unix", mi->created);
1709 }
1710
1711 gc_free(&gc);
1712}
1713
1720static bool
1722{
1723 struct tls_multi *tls_multi = c->c2.tls_multi;
1724 const char *const peer_info = tls_multi->peer_info;
1725 struct options *o = &c->options;
1726
1727
1728 unsigned int proto = extract_iv_proto(peer_info);
1729 if (proto & IV_PROTO_DATA_V2)
1730 {
1731 tls_multi->use_peer_id = true;
1732 o->use_peer_id = true;
1733 }
1734 else if (dco_enabled(o))
1735 {
1736 msg(M_INFO, "Client does not support DATA_V2. Data channel offloading "
1737 "requires DATA_V2. Dropping client.");
1738 auth_set_client_reason(tls_multi, "Data channel negotiation "
1739 "failed (missing DATA_V2)");
1740 return false;
1741 }
1742
1743 /* Print a warning if we detect the client being in P2P mode and will
1744 * not accept our pushed ciphers */
1745 if (proto & IV_PROTO_NCP_P2P)
1746 {
1747 msg(M_WARN, "Note: peer reports running in P2P mode (no --pull/--client "
1748 "option). It will not negotiate ciphers with this server. "
1749 "Expect this connection to fail.");
1750 }
1751
1752 if (proto & IV_PROTO_REQUEST_PUSH)
1753 {
1754 c->c2.push_request_received = true;
1755 }
1756
1757 if (proto & IV_PROTO_TLS_KEY_EXPORT)
1758 {
1760 }
1761 else if (o->force_key_material_export)
1762 {
1763 msg(M_INFO, "PUSH: client does not support TLS Keying Material "
1764 "Exporters but --force-tls-key-material-export is enabled.");
1765 auth_set_client_reason(tls_multi, "Client incompatible with this "
1766 "server. Keying Material Exporters (RFC 5705) "
1767 "support missing. Upgrade to a client that "
1768 "supports this feature (OpenVPN 2.6.0+).");
1769 return false;
1770 }
1771 if (proto & IV_PROTO_DYN_TLS_CRYPT)
1772 {
1774 }
1775
1776 if (proto & IV_PROTO_CC_EXIT_NOTIFY)
1777 {
1779 }
1780
1781 /* Select cipher if client supports Negotiable Crypto Parameters */
1782
1783 /* if we have already created our key, we cannot *change* our own
1784 * cipher -> so log the fact and push the "what we have now" cipher
1785 * (so the client is always told what we expect it to use)
1786 */
1788 {
1789 msg(M_INFO,
1790 "PUSH: client wants to negotiate cipher (NCP), but "
1791 "server has already generated data channel keys, "
1792 "re-sending previously negotiated cipher '%s'",
1793 o->ciphername);
1794 return true;
1795 }
1796
1797 /*
1798 * Push the first cipher from --data-ciphers to the client that
1799 * the client announces to be supporting.
1800 */
1801 const char *push_cipher =
1803 if (push_cipher)
1804 {
1805 /* Enable epoch data key format if supported and AEAD cipher in use */
1807 && cipher_kt_mode_aead(push_cipher))
1808 {
1810 }
1811
1812 o->ciphername = push_cipher;
1813 return true;
1814 }
1815
1816 /* NCP cipher negotiation failed. Try to figure out why exactly it
1817 * failed and give good error messages and potentially do a fallback
1818 * for non NCP clients */
1819 struct gc_arena gc = gc_new();
1820 bool ret = false;
1821
1822 const char *peer_ciphers = tls_peer_ncp_list(peer_info, &gc);
1823 /* If we are in a situation where we know the client ciphers, there is no
1824 * reason to fall back to a cipher that will not be accepted by the other
1825 * side, in this situation we fail the auth*/
1826 if (strlen(peer_ciphers) > 0)
1827 {
1828 msg(M_INFO,
1829 "PUSH: No common cipher between server and client. "
1830 "Server data-ciphers: '%s'%s, client supported ciphers '%s'",
1831 o->ncp_ciphers_conf, ncp_expanded_ciphers(o, &gc), peer_ciphers);
1832 }
1833 else if (tls_multi->remote_ciphername)
1834 {
1835 msg(M_INFO,
1836 "PUSH: No common cipher between server and client. "
1837 "Server data-ciphers: '%s'%s, client supports cipher '%s'",
1839 }
1840 else
1841 {
1842 msg(M_INFO, "PUSH: No NCP or OCC cipher data received from peer.");
1843
1844 if (o->enable_ncp_fallback)
1845 {
1846 msg(M_INFO,
1847 "Using data channel cipher '%s' since "
1848 "--data-ciphers-fallback is set.",
1849 o->ciphername);
1850 ret = true;
1851 }
1852 else
1853 {
1854 msg(M_INFO, "Use --data-ciphers-fallback with the cipher the "
1855 "client is using if you want to allow the client to connect");
1856 }
1857 }
1858 if (!ret)
1859 {
1860 auth_set_client_reason(tls_multi, "Data channel cipher negotiation "
1861 "failed (no shared cipher)");
1862 }
1863
1864 gc_free(&gc);
1865 return ret;
1866}
1867
1872static void
1874{
1876 if (!ccs->deferred_ret_file)
1877 {
1878 return;
1879 }
1880
1881 setenv_del(mi->context.c2.es, "client_connect_deferred_file");
1883 {
1884 msg(D_MULTI_ERRORS, "MULTI: problem deleting temporary file: %s", ccs->deferred_ret_file);
1885 }
1886 free(ccs->deferred_ret_file);
1887 ccs->deferred_ret_file = NULL;
1888}
1889
1897static bool
1899{
1901 struct gc_arena gc = gc_new();
1902 const char *fn;
1903
1904 /* Delete file if it already exists */
1906
1908 if (!fn)
1909 {
1910 gc_free(&gc);
1911 return false;
1912 }
1913 ccs->deferred_ret_file = string_alloc(fn, NULL);
1914
1915 setenv_str(mi->context.c2.es, "client_connect_deferred_file", ccs->deferred_ret_file);
1916
1917 gc_free(&gc);
1918 return true;
1919}
1920
1929static enum client_connect_return
1931{
1932 const struct client_connect_defer_state *ccs = &(mi->client_connect_defer_state);
1933 FILE *fp = fopen(ccs->deferred_ret_file, "r");
1934 if (!fp)
1935 {
1936 return CC_RET_SKIPPED;
1937 }
1938
1940 const int c = fgetc(fp);
1941 switch (c)
1942 {
1943 case '0':
1944 ret = CC_RET_FAILED;
1945 break;
1946
1947 case '1':
1948 ret = CC_RET_SUCCEEDED;
1949 break;
1950
1951 case '2':
1952 ret = CC_RET_DEFERRED;
1953 break;
1954
1955 case EOF:
1956 if (feof(fp))
1957 {
1958 ret = CC_RET_SKIPPED;
1959 break;
1960 }
1961
1962 /* Not EOF but other error -> fall through to error state */
1963 default:
1964 /* We received an unknown/unexpected value. Assume failure. */
1965 msg(M_WARN, "WARNING: Unknown/unexpected value in deferred "
1966 "client-connect resultfile");
1967 ret = CC_RET_FAILED;
1968 }
1969 fclose(fp);
1970
1971 return ret;
1972}
1973
1979static void
1981{
1983 if (ccs->config_file)
1984 {
1985 setenv_del(mi->context.c2.es, "client_connect_config_file");
1986 if (!platform_unlink(ccs->config_file))
1987 {
1988 msg(D_MULTI_ERRORS, "MULTI: problem deleting temporary file: %s", ccs->config_file);
1989 }
1990 free(ccs->config_file);
1991 ccs->config_file = NULL;
1992 }
1993}
1994
2002static bool
2004{
2006 struct gc_arena gc = gc_new();
2007 const char *fn;
2008
2009 if (ccs->config_file)
2010 {
2012 }
2013
2015 if (!fn)
2016 {
2017 gc_free(&gc);
2018 return false;
2019 }
2020 ccs->config_file = string_alloc(fn, NULL);
2021
2022 setenv_str(mi->context.c2.es, "client_connect_config_file", ccs->config_file);
2023
2024 gc_free(&gc);
2025 return true;
2026}
2027
2028static enum client_connect_return
2030 bool deferred, uint64_t *option_types_found)
2031{
2033#ifdef ENABLE_PLUGIN
2034 ASSERT(m);
2035 ASSERT(mi);
2036 ASSERT(option_types_found);
2038
2039 /* deprecated callback, use a file for passing back return info */
2040 if (plugin_defined(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_CONNECT))
2041 {
2042 struct argv argv = argv_new();
2043 int call;
2044
2045 if (!deferred)
2046 {
2047 call = OPENVPN_PLUGIN_CLIENT_CONNECT;
2049 {
2050 ret = CC_RET_FAILED;
2051 goto cleanup;
2052 }
2053 }
2054 else
2055 {
2056 call = OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER;
2057 /* the initial call should have created these files */
2058 ASSERT(ccs->config_file);
2060 }
2061
2062 argv_printf(&argv, "%s", ccs->config_file);
2063 int plug_ret = plugin_call(mi->context.plugins, call, &argv, NULL, mi->context.c2.es);
2064 if (plug_ret == OPENVPN_PLUGIN_FUNC_SUCCESS)
2065 {
2066 ret = CC_RET_SUCCEEDED;
2067 }
2068 else if (plug_ret == OPENVPN_PLUGIN_FUNC_DEFERRED)
2069 {
2070 ret = CC_RET_DEFERRED;
2076 }
2077 else
2078 {
2079 msg(M_WARN, "WARNING: client-connect plugin call failed");
2080 ret = CC_RET_FAILED;
2081 }
2082
2083
2089 int file_ret = ccs_test_deferred_ret_file(mi);
2090
2091 if (file_ret == CC_RET_FAILED)
2092 {
2093 ret = CC_RET_FAILED;
2094 }
2095 else if (ret == CC_RET_SUCCEEDED && file_ret == CC_RET_DEFERRED)
2096 {
2097 ret = CC_RET_DEFERRED;
2098 }
2099
2100 /* if we still think we have succeeded, do postprocessing */
2101 if (ret == CC_RET_SUCCEEDED)
2102 {
2103 multi_client_connect_post(m, mi, ccs->config_file, option_types_found);
2104 }
2105cleanup:
2106 argv_free(&argv);
2107
2108 if (ret != CC_RET_DEFERRED)
2109 {
2112 }
2113 }
2114#endif /* ifdef ENABLE_PLUGIN */
2115 return ret;
2116}
2117
2118static enum client_connect_return
2120 bool deferred, uint64_t *option_types_found)
2121{
2123#ifdef ENABLE_PLUGIN
2124 ASSERT(m);
2125 ASSERT(mi);
2126 ASSERT(option_types_found);
2127
2128 int call = deferred ? OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER_V2 : OPENVPN_PLUGIN_CLIENT_CONNECT_V2;
2129 /* V2 callback, use a plugin_return struct for passing back return info */
2130 if (plugin_defined(mi->context.plugins, call))
2131 {
2132 struct plugin_return pr;
2133
2134 plugin_return_init(&pr);
2135
2136 int plug_ret = plugin_call(mi->context.plugins, call, NULL, &pr, mi->context.c2.es);
2137 if (plug_ret == OPENVPN_PLUGIN_FUNC_SUCCESS)
2138 {
2139 multi_client_connect_post_plugin(m, mi, &pr, option_types_found);
2140 ret = CC_RET_SUCCEEDED;
2141 }
2142 else if (plug_ret == OPENVPN_PLUGIN_FUNC_DEFERRED)
2143 {
2144 ret = CC_RET_DEFERRED;
2145 if (!(plugin_defined(mi->context.plugins, OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER_V2)))
2146 {
2147 msg(M_WARN, "A plugin that defers from the "
2148 "OPENVPN_PLUGIN_CLIENT_CONNECT_V2 call must also "
2149 "declare support for "
2150 "OPENVPN_PLUGIN_CLIENT_CONNECT_DEFER_V2");
2151 ret = CC_RET_FAILED;
2152 }
2153 }
2154 else
2155 {
2156 msg(M_WARN, "WARNING: client-connect-v2 plugin call failed");
2157 ret = CC_RET_FAILED;
2158 }
2159
2160
2161 plugin_return_free(&pr);
2162 }
2163#endif /* ifdef ENABLE_PLUGIN */
2164 return ret;
2165}
2166
2167static enum client_connect_return
2169 uint64_t *option_types_found)
2170{
2171 ASSERT(mi);
2172 ASSERT(option_types_found);
2173 const struct client_connect_defer_state *ccs = &(mi->client_connect_defer_state);
2175
2177
2178 if (ret == CC_RET_SKIPPED)
2179 {
2180 /*
2181 * Skipped and deferred are equivalent in this context.
2182 * skipped means that the called program has not yet
2183 * written a return status implicitly needing more time
2184 * while deferred is the explicit notification that it
2185 * needs more time
2186 */
2187 ret = CC_RET_DEFERRED;
2188 }
2189
2190 if (ret == CC_RET_SUCCEEDED)
2191 {
2195 }
2196 if (ret == CC_RET_FAILED)
2197 {
2198 msg(M_INFO, "MULTI: deferred --client-connect script returned CC_RET_FAILED");
2201 }
2202 return ret;
2203}
2204
2208static enum client_connect_return
2210 uint64_t *option_types_found)
2211{
2212 if (deferred)
2213 {
2215 }
2216 ASSERT(m);
2217 ASSERT(mi);
2218
2221
2223 {
2224 struct argv argv = argv_new();
2225 struct gc_arena gc = gc_new();
2226
2227 setenv_str(mi->context.c2.es, "script_type", "client-connect");
2228
2230 {
2231 ret = CC_RET_FAILED;
2232 goto cleanup;
2233 }
2234
2236 argv_printf_cat(&argv, "%s", ccs->config_file);
2237
2238 if (openvpn_run_script(&argv, mi->context.c2.es, 0, "--client-connect"))
2239 {
2241 {
2242 ret = CC_RET_DEFERRED;
2243 }
2244 else
2245 {
2246 multi_client_connect_post(m, mi, ccs->config_file, option_types_found);
2247 ret = CC_RET_SUCCEEDED;
2248 }
2249 }
2250 else
2251 {
2252 ret = CC_RET_FAILED;
2253 }
2254cleanup:
2255 if (ret != CC_RET_DEFERRED)
2256 {
2259 }
2260 argv_free(&argv);
2261 gc_free(&gc);
2262 }
2263 return ret;
2264}
2265
2266static bool
2268 struct gc_arena *gc)
2269{
2270 if (!dco_enabled(&mi->context.options))
2271 {
2272 /* DCO not enabled, nothing to do, return sucess */
2273 return true;
2274 }
2275 int ret = dco_multi_add_new_peer(m, mi);
2276 if (ret < 0)
2277 {
2278 msg(D_DCO, "Cannot add peer to DCO for %s: %s (%d)", multi_instance_string(mi, false, gc),
2279 strerror(-ret), ret);
2280 return false;
2281 }
2282
2283 return true;
2284}
2285
2289static bool
2291{
2292 struct frame *frame_fragment = NULL;
2293#ifdef ENABLE_FRAGMENT
2294 if (c->options.ce.fragment)
2295 {
2296 frame_fragment = &c->c2.frame_fragment;
2297 }
2298#endif
2301 frame_fragment, get_link_socket_info(c),
2302 &c->c1.tuntap->dco))
2303 {
2304 msg(D_TLS_ERRORS, "TLS Error: initializing data channel failed");
2305 register_signal(c->sig, SIGUSR1, "process-push-msg-failed");
2306 return false;
2307 }
2308
2309 return true;
2310}
2311
2312static void
2314 const uint64_t option_types_found)
2315{
2316 ASSERT(m);
2317 ASSERT(mi);
2318
2319 struct gc_arena gc = gc_new();
2320 /*
2321 * Process sourced options.
2322 */
2323 do_deferred_options(&mi->context, option_types_found, false);
2324
2325 /*
2326 * make sure we got ifconfig settings from somewhere
2327 */
2329 {
2331 "MULTI: no dynamic or static remote "
2332 "--ifconfig address is available for %s",
2333 multi_instance_string(mi, false, &gc));
2334 }
2335
2336 /*
2337 * make sure that ifconfig settings comply with constraints
2338 */
2340 {
2341 const char *ifconfig_constraint_network =
2343 const char *ifconfig_constraint_netmask =
2345
2346 /* JYFIXME -- this should cause the connection to fail */
2348 "MULTI ERROR: primary virtual IP for %s (%s) "
2349 "violates tunnel network/netmask constraint (%s/%s)",
2350 multi_instance_string(mi, false, &gc),
2352 ifconfig_constraint_network, ifconfig_constraint_netmask);
2353 }
2354
2355 /* set our client's VPN endpoint for status reporting purposes */
2358
2359 /* set context-level authentication flag */
2361
2362 /* Since dco-win maintains iroute routing table (subnet -> peer),
2363 * peer must be added before iroutes. For other platforms it doesn't matter. */
2364
2365 /* authentication complete, calculate dynamic client specific options */
2367 {
2369 }
2370 /* only continue if setting protocol options worked */
2371 else if (!multi_client_setup_dco_initial(m, mi, &gc))
2372 {
2374 }
2375 /* Generate data channel keys only if setting protocol options
2376 * and DCO initial setup has not failed */
2378 {
2380 }
2381
2382 /* dco peer has been added, it is now safe for Windows to add iroutes */
2383
2384 /*
2385 * For routed tunnels, set up internal route to endpoint
2386 * plus add all iroute routes.
2387 */
2389 {
2391 {
2393 msg(D_MULTI_LOW, "MULTI: primary virtual IP for %s: %s",
2394 multi_instance_string(mi, false, &gc),
2396 }
2397
2399 {
2401 /* TODO: find out where addresses are "unlearned"!! */
2402 const char *ifconfig_local_ipv6 =
2404 msg(D_MULTI_LOW, "MULTI: primary virtual IPv6 for %s: %s",
2405 multi_instance_string(mi, false, &gc), ifconfig_local_ipv6);
2406 }
2407
2408 /* add routes locally, pointing to new client, if
2409 * --iroute options have been specified */
2410 multi_add_iroutes(m, mi);
2411
2412 /*
2413 * iroutes represent subnets which are "owned" by a particular
2414 * client. Therefore, do not actually push a route to a client
2415 * if it matches one of the client's iroutes.
2416 */
2418 }
2419 else if (mi->context.options.iroutes)
2420 {
2422 "MULTI: --iroute options rejected for %s -- iroute "
2423 "only works with tun-style tunnels",
2424 multi_instance_string(mi, false, &gc));
2425 }
2426
2427 /* send push reply if ready */
2429 {
2431 }
2432 gc_free(&gc);
2433}
2434
2435static void
2437{
2438 ASSERT(mi->context.c1.tuntap);
2439 /*
2440 * lock down the common name and cert hashes so they can't change
2441 * during future TLS renegotiations
2442 */
2445
2446 /* generate a msg() prefix for this client instance */
2447 generate_prefix(mi);
2448
2449 /* delete instances of previous clients with same common-name */
2450 if (!mi->context.options.duplicate_cn)
2451 {
2452 multi_delete_dup(m, mi);
2453 }
2454
2455 /* reset pool handle to null */
2456 mi->vaddr_handle = -1;
2457
2458 /* do --client-connect setenvs */
2460
2462}
2463
2470static enum client_connect_return
2472 bool deferred, uint64_t *option_types_found)
2473{
2474#ifdef USE_COMP
2475 struct options *o = &mi->context.options;
2476 const char *const peer_info = mi->context.c2.tls_multi->peer_info;
2477
2479 {
2480 if (peer_info && strstr(peer_info, "IV_COMP_STUBv2=1"))
2481 {
2482 push_option(o, "compress stub-v2", M_USAGE);
2483 }
2484 else
2485 {
2486 /* Client is old and does not support STUBv2 but since it
2487 * announced comp-lzo via OCC we assume it uses comp-lzo, so
2488 * switch to that and push the uncompressed variant. */
2489 push_option(o, "comp-lzo no", M_USAGE);
2490 o->comp.alg = COMP_ALG_STUB;
2491 *option_types_found |= OPT_P_COMP;
2492 }
2493 }
2494#endif
2495 return CC_RET_SUCCEEDED;
2496}
2497
2502static enum client_connect_return
2504 uint64_t *option_types_found)
2505{
2506 /* Since we never return a CC_RET_DEFERRED, this indicates a serious
2507 * problem */
2508 ASSERT(!deferred);
2511 {
2512 struct gc_arena gc = gc_new();
2513 const char *ccd_file = NULL;
2514
2515 const char *ccd_client =
2517 tls_common_name(mi->context.c2.tls_multi, false), &gc);
2518
2519 const char *ccd_default =
2521
2522
2523 /* try common-name file */
2524 if (platform_test_file(ccd_client))
2525 {
2526 ccd_file = ccd_client;
2527 }
2528 /* try default file */
2529 else if (platform_test_file(ccd_default))
2530 {
2531 ccd_file = ccd_default;
2532 }
2533
2534 if (ccd_file)
2535 {
2537 CLIENT_CONNECT_OPT_MASK, option_types_found, mi->context.c2.es);
2538 /*
2539 * Select a virtual address from either --ifconfig-push in
2540 * --client-config-dir file or --ifconfig-pool.
2541 */
2543
2545
2546 ret = CC_RET_SUCCEEDED;
2547 }
2548 gc_free(&gc);
2549 }
2550 return ret;
2551}
2552
2554 struct multi_context *m, struct multi_instance *mi, bool from_deferred,
2555 uint64_t *option_types_found);
2556
2566
2571static bool
2573{
2574 struct tls_multi *multi = mi->context.c2.tls_multi;
2575 const struct options *options = &mi->context.options;
2576 struct tls_session *session = &multi->session[TM_ACTIVE];
2577
2578 if (!multi->locked_username)
2579 {
2580 msg(D_MULTI_ERRORS, "MULTI: Ignoring override-username as no "
2581 "user/password method is enabled. Enable "
2582 "--management-client-auth, --auth-user-pass-verify, or a "
2583 "plugin with user/password verify capability.");
2584 return false;
2585 }
2586
2587 if (!multi->locked_original_username
2588 && strcmp(multi->locked_username, options->override_username) != 0)
2589 {
2590 /* Check if the username length is acceptable */
2592 {
2593 return false;
2594 }
2595
2597 multi->locked_username = strdup(options->override_username);
2598
2599 /* Override also the common name if username should be set as common
2600 * name */
2601 if ((session->opt->ssl_flags & SSLF_USERNAME_AS_COMMON_NAME))
2602 {
2604 free(multi->locked_cn);
2605 multi->locked_cn = NULL;
2606 tls_lock_common_name(multi);
2607 }
2608
2609 /* Regenerate the auth-token if enabled */
2610 if (multi->auth_token_initial)
2611 {
2612 struct user_pass up;
2613 CLEAR(up);
2614 strncpynt(up.username, multi->locked_username, sizeof(up.username));
2615
2616 generate_auth_token(&up, multi);
2617 }
2618
2620 "MULTI: Note, override-username changes username "
2621 "from '%s' to '%s'",
2623 }
2624 return true;
2625}
2626/*
2627 * Called as soon as the SSL/TLS connection is authenticated.
2628 *
2629 * Will collect the client specific configuration from the different
2630 * sources like ccd files, connect plugins and management interface.
2631 *
2632 * This method starts with cas_context CAS_PENDING and will move the
2633 * state machine to either CAS_SUCCEEDED on success or
2634 * CAS_FAILED/CAS_PARTIAL on failure.
2635 *
2636 * Instance-specific directives to be processed (CLIENT_CONNECT_OPT_MASK)
2637 * include:
2638 *
2639 * iroute start-ip end-ip
2640 * ifconfig-push local remote-netmask
2641 * push
2642 *
2643 *
2644 */
2645static void
2647{
2648 /* We are only called for the CAS_PENDING_x states, so we
2649 * can ignore other states here */
2650 bool from_deferred = (mi->context.c2.tls_multi->multi_state != CAS_PENDING);
2651
2652 int *cur_handler_index = &mi->client_connect_defer_state.cur_handler_index;
2653 uint64_t *option_types_found = &mi->client_connect_defer_state.option_types_found;
2654
2655 /* We are called for the first time */
2656 if (!from_deferred)
2657 {
2658 *cur_handler_index = 0;
2659 *option_types_found = 0;
2660 /* Initially we have no handler that has returned a result */
2662
2664 }
2665
2666 bool cc_succeeded = true;
2667
2668 while (cc_succeeded && client_connect_handlers[*cur_handler_index] != NULL)
2669 {
2670 enum client_connect_return ret;
2671 ret = client_connect_handlers[*cur_handler_index](m, mi, from_deferred, option_types_found);
2672
2673 from_deferred = false;
2674
2675 switch (ret)
2676 {
2677 case CC_RET_SUCCEEDED:
2678 /*
2679 * Remember that we already had at least one handler
2680 * returning a result should we go to into deferred state
2681 */
2682 mi->context.c2.tls_multi->multi_state = CAS_PENDING_DEFERRED_PARTIAL;
2683 break;
2684
2685 case CC_RET_SKIPPED:
2686 /*
2687 * Move on with the next handler without modifying any
2688 * other state
2689 */
2690 break;
2691
2692 case CC_RET_DEFERRED:
2693 /*
2694 * we already set multi_status to DEFERRED_RESULT or
2695 * DEFERRED_NO_RESULT. We just return
2696 * from the function as having multi_status
2697 */
2698 return;
2699
2700 case CC_RET_FAILED:
2701 /*
2702 * One handler failed. We abort the chain and set the final
2703 * result to failed
2704 */
2705 cc_succeeded = false;
2706 break;
2707
2708 default:
2709 ASSERT(0);
2710 }
2711
2712 /*
2713 * Check for "disable" directive in client-config-dir file
2714 * or config file generated by --client-connect script.
2715 */
2716 if (mi->context.options.disable)
2717 {
2718 msg(D_MULTI_ERRORS, "MULTI: client has been rejected due to "
2719 "'disable' directive");
2720 cc_succeeded = false;
2721 }
2722
2723 (*cur_handler_index)++;
2724 }
2725
2727 {
2728 if (!override_locked_username(mi))
2729 {
2730 cc_succeeded = false;
2731 }
2732 }
2733
2734 /* Check if we have forbidding options in the current mode */
2735 if (dco_enabled(&mi->context.options)
2737 {
2738 msg(D_MULTI_ERRORS, "MULTI: client has been rejected due to incompatible DCO options");
2739 cc_succeeded = false;
2740 }
2741
2743 {
2744 msg(D_MULTI_ERRORS, "MULTI: client has been rejected due to invalid compression options");
2745 cc_succeeded = false;
2746 }
2747
2748 if (cc_succeeded)
2749 {
2750 multi_client_connect_late_setup(m, mi, *option_types_found);
2751 }
2752 else
2753 {
2754 /* run the disconnect script if we had a connect script that
2755 * did not fail */
2757 {
2759 }
2760
2762 }
2763
2764 /* increment number of current authenticated clients */
2765 ++m->n_clients;
2766 --mi->n_clients_delta;
2767
2768#ifdef ENABLE_MANAGEMENT
2769 if (management)
2770 {
2772 mi->context.c2.es);
2773 }
2774#endif
2775}
2776
2777#ifdef ENABLE_ASYNC_PUSH
2778/*
2779 * Called when inotify event is fired, which happens when acf
2780 * or connect-status file is closed or deleted.
2781 * Continues authentication and sends push_reply
2782 * (or be deferred again by client-connect)
2783 */
2784void
2785multi_process_file_closed(struct multi_context *m, const unsigned int mpp_flags)
2786{
2787 char buffer[INOTIFY_EVENT_BUFFER_SIZE];
2788 ssize_t buffer_i = 0;
2789 ssize_t r = read(m->top.c2.inotify_fd, buffer, INOTIFY_EVENT_BUFFER_SIZE);
2790 if (r < 0)
2791 {
2792 msg(M_WARN | M_ERRNO, "MULTI: multi_process_file_closed error");
2793 return;
2794 }
2795
2796 while (buffer_i < r)
2797 {
2798 /* parse inotify events */
2799 struct inotify_event *pevent = (struct inotify_event *)&buffer[buffer_i];
2800 size_t event_size = sizeof(struct inotify_event) + pevent->len;
2801 buffer_i += event_size;
2802
2803 msg(D_MULTI_DEBUG, "MULTI: modified fd %d, mask %d", pevent->wd, pevent->mask);
2804
2805 struct multi_instance *mi =
2806 hash_lookup(m->inotify_watchers, (void *)(uintptr_t)pevent->wd);
2807
2808 if (pevent->mask & IN_CLOSE_WRITE)
2809 {
2810 if (mi)
2811 {
2812 /* continue authentication, perform NCP negotiation and send push_reply */
2813 multi_process_post(m, mi, mpp_flags);
2814 }
2815 else
2816 {
2817 msg(D_MULTI_ERRORS, "MULTI: multi_instance not found!");
2818 }
2819 }
2820 else if (pevent->mask & IN_IGNORED)
2821 {
2822 /* this event is _always_ fired when watch is removed or file is deleted */
2823 if (mi)
2824 {
2825 hash_remove(m->inotify_watchers, (void *)(uintptr_t)pevent->wd);
2826 mi->inotify_watch = -1;
2827 }
2828 }
2829 else
2830 {
2831 msg(D_MULTI_ERRORS, "MULTI: unknown mask %d", pevent->mask);
2832 }
2833 }
2834}
2835#endif /* ifdef ENABLE_ASYNC_PUSH */
2836
2837/*
2838 * Add a mbuf buffer to a particular
2839 * instance.
2840 */
2841static void
2842multi_add_mbuf(struct multi_context *m, struct multi_instance *mi, struct mbuf_buffer *mb)
2843{
2844 if (multi_output_queue_ready(m, mi))
2845 {
2846 struct mbuf_item item;
2847 item.buffer = mb;
2848 item.instance = mi;
2849 mbuf_add_item(m->mbuf, &item);
2850 }
2851 else
2852 {
2853 msg(D_MULTI_DROPPED, "MULTI: packet dropped due to output saturation (multi_add_mbuf)");
2854 }
2855}
2856
2857/*
2858 * Add a packet to a client instance output queue.
2859 */
2860static inline void
2861multi_unicast(struct multi_context *m, const struct buffer *buf, struct multi_instance *mi)
2862{
2863 struct mbuf_buffer *mb;
2864
2865 if (BLEN(buf) > 0)
2866 {
2867 mb = mbuf_alloc_buf(buf);
2868 mb->flags = MF_UNICAST;
2869 multi_add_mbuf(m, mi, mb);
2870 mbuf_free_buf(mb);
2871 }
2872}
2873
2874/*
2875 * Broadcast a packet to all clients.
2876 */
2877static void
2878multi_bcast(struct multi_context *m, const struct buffer *buf,
2879 const struct multi_instance *sender_instance, uint16_t vid)
2880{
2881 struct mbuf_buffer *mb;
2882
2883 if (BLEN(buf) > 0)
2884 {
2885#ifdef MULTI_DEBUG_EVENT_LOOP
2886 printf("BCAST len=%d\n", BLEN(buf));
2887#endif
2888 mb = mbuf_alloc_buf(buf);
2889
2890 for (uint32_t i = 0; i <= m->max_peerid; i++)
2891 {
2892 struct multi_instance *mi = m->instances[i];
2893
2894 if (mi && mi != sender_instance && !mi->halt)
2895 {
2896 if (vid != 0 && vid != mi->context.options.vlan_pvid)
2897 {
2898 continue;
2899 }
2900 multi_add_mbuf(m, mi, mb);
2901 }
2902 }
2903 mbuf_free_buf(mb);
2904 }
2905}
2906
2907/*
2908 * Given a time delta, indicating that we wish to be
2909 * awoken by the scheduler at time now + delta, figure
2910 * a sigma parameter (in microseconds) that represents
2911 * a sort of fuzz factor around delta, so that we're
2912 * really telling the scheduler to wake us up any time
2913 * between now + delta - sigma and now + delta + sigma.
2914 *
2915 * The sigma parameter helps the scheduler to run more efficiently.
2916 * Sigma should be no larger than TV_WITHIN_SIGMA_MAX_USEC
2917 */
2918static inline unsigned int
2919compute_wakeup_sigma(const struct timeval *delta)
2920{
2921 ASSERT(delta->tv_sec >= 0);
2922 ASSERT(delta->tv_usec >= 0);
2923 if (delta->tv_sec < 1)
2924 {
2925 /* if < 1 sec, fuzz = # of microseconds / 8 */
2926 return (unsigned int)(delta->tv_usec >> 3);
2927 }
2928 else
2929 {
2930 /* if < 10 minutes, fuzz = 13.1% of timeout */
2931 if (delta->tv_sec < 600)
2932 {
2933 return (unsigned int)(delta->tv_sec << 17);
2934 }
2935 else
2936 {
2937 return 120 * 1000000; /* if >= 10 minutes, fuzz = 2 minutes */
2938 }
2939 }
2940}
2941
2942static void
2944{
2945 /* calculate an absolute wakeup time */
2946 ASSERT(!openvpn_gettimeofday(&mi->wakeup, NULL));
2947 tv_add(&mi->wakeup, &mi->context.c2.timeval);
2948
2949 /* tell scheduler to wake us up at some point in the future */
2950 schedule_add_entry(m->schedule, (struct schedule_entry *)mi, &mi->wakeup,
2952}
2953
2954#if defined(ENABLE_ASYNC_PUSH)
2955static void
2956add_inotify_file_watch(struct multi_context *m, struct multi_instance *mi, int inotify_fd,
2957 const char *file)
2958{
2959 /* watch acf file */
2960 int watch_descriptor = inotify_add_watch(inotify_fd, file, IN_CLOSE_WRITE | IN_ONESHOT);
2961 if (watch_descriptor >= 0)
2962 {
2963 if (mi->inotify_watch != -1)
2964 {
2965 hash_remove(m->inotify_watchers, (void *)(uintptr_t)mi->inotify_watch);
2966 }
2967 hash_add(m->inotify_watchers, (void *)(uintptr_t)watch_descriptor, mi, true);
2968 mi->inotify_watch = watch_descriptor;
2969 }
2970 else
2971 {
2972 msg(M_NONFATAL | M_ERRNO, "MULTI: inotify_add_watch error");
2973 }
2974}
2975#endif /* if defined(ENABLE_ASYNC_PUSH) */
2976
2977/*
2978 * Figure instance-specific timers, convert
2979 * earliest to absolute time in mi->wakeup,
2980 * call scheduler with our future wakeup time.
2981 *
2982 * Also close context on signal.
2983 */
2984bool
2985multi_process_post(struct multi_context *m, struct multi_instance *mi, const unsigned int flags)
2986{
2987 bool ret = true;
2988
2989 if (!IS_SIG(&mi->context)
2990 && ((flags & MPP_PRE_SELECT)))
2991 {
2992#if defined(ENABLE_ASYNC_PUSH)
2993 bool was_unauthenticated = true;
2994 const struct key_state *ks = NULL;
2995 if (mi->context.c2.tls_multi)
2996 {
2998 was_unauthenticated = (ks->authenticated == KS_AUTH_FALSE);
2999 }
3000#endif
3001
3002 /* figure timeouts and fetch possible outgoing
3003 * to_link packets (such as ping or TLS control) */
3004 pre_select(&mi->context);
3005
3006#if defined(ENABLE_ASYNC_PUSH)
3007 /*
3008 * if we see the state transition from unauthenticated to deferred
3009 * and an auth_control_file, we assume it got just added and add
3010 * inotify watch to that file
3011 */
3012 if (ks && ks->plugin_auth.auth_control_file && was_unauthenticated
3013 && (ks->authenticated == KS_AUTH_DEFERRED))
3014 {
3015 add_inotify_file_watch(m, mi, m->top.c2.inotify_fd, ks->plugin_auth.auth_control_file);
3016 }
3017 if (ks && ks->script_auth.auth_control_file && was_unauthenticated
3018 && (ks->authenticated == KS_AUTH_DEFERRED))
3019 {
3020 add_inotify_file_watch(m, mi, m->top.c2.inotify_fd, ks->script_auth.auth_control_file);
3021 }
3022#endif
3023
3024 if (!IS_SIG(&mi->context))
3025 {
3026 /* connection is "established" when SSL/TLS key negotiation succeeds
3027 * and (if specified) auth user/pass succeeds */
3028
3030 {
3032 }
3033#if defined(ENABLE_ASYNC_PUSH)
3036 {
3037 add_inotify_file_watch(m, mi, m->top.c2.inotify_fd,
3039 }
3040#endif
3041 /* tell scheduler to wake us up at some point in the future */
3043 }
3044 }
3045
3046 if (IS_SIG(&mi->context))
3047 {
3048 if (flags & MPP_CLOSE_ON_SIGNAL)
3049 {
3051 ret = false;
3052 }
3053 }
3054 else
3055 {
3056 /* continue to pend on output? */
3057 multi_set_pending(m, ANY_OUT(&mi->context) ? mi : NULL);
3058
3059#ifdef MULTI_DEBUG_EVENT_LOOP
3060 printf("POST %s[%d] to=%d lo=%d/%d w=%" PRIi64 "/%ld\n", id(mi), (int)(mi == m->pending),
3062 mi->context.c2.fragment ? mi->context.c2.fragment->outgoing.len : -1,
3063 (int64_t)mi->context.c2.timeval.tv_sec, (long)mi->context.c2.timeval.tv_usec);
3064#endif
3065 }
3066
3067 if ((flags & MPP_RECORD_TOUCH) && m->mpp_touched)
3068 {
3069 *m->mpp_touched = mi;
3070 }
3071
3072 return ret;
3073}
3074
3085static bool
3087{
3088 struct hash *hash = m->hash;
3089 const uint64_t hv = hash_value(hash, real);
3090 struct hash_bucket *bucket = hash_bucket(hash, hv);
3091
3092 /* make sure that we don't assign the client to an address taken by
3093 * another client */
3094 struct hash_element *he = hash_lookup_fast(hash, bucket, real, hv);
3095 if (!he)
3096 {
3097 /* Address is not taken, everything is fine. */
3098 return true;
3099 }
3100
3101 struct multi_instance *ex_mi = he->value;
3102
3103 const struct tls_multi *m1 = mi->context.c2.tls_multi;
3104 const struct tls_multi *m2 = ex_mi->context.c2.tls_multi;
3105
3106 struct gc_arena gc = gc_new();
3107 int ret = false;
3108
3109 /* do not allow if target address is taken by client with another cert */
3111 {
3112 msg(D_MULTI_LOW, "Disallow float to an address taken by another client %s",
3113 multi_instance_string(ex_mi, false, &gc));
3114
3115 mi->context.c2.buf.len = 0;
3116 goto done;
3117 }
3118
3119 /* do not allow if target address has a different username */
3120 if (m1->locked_username || m2->locked_username)
3121 {
3122 if (!m1->locked_username || !m2->locked_username
3123 || strcmp(m1->locked_username, m2->locked_username) != 0)
3124 {
3125 msg(D_MULTI_LOW, "Disallow float to an address taken by another client %s",
3126 multi_instance_string(ex_mi, false, &gc));
3127 goto done;
3128 }
3129 }
3130
3131 /* It doesn't make sense to let a peer float to the address it already
3132 * has, so we disallow it. This can happen if a DCO netlink notification
3133 * gets lost and we miss a floating step.
3134 */
3135 if (m1->rx_peer_id == m2->rx_peer_id)
3136 {
3137 msg(M_WARN,
3138 "disallowing peer %" PRIu32 " (%s) from floating to "
3139 "its own address (%s)",
3141 mroute_addr_print(&mi->real, &gc));
3142 goto done;
3143 }
3144
3146 "closing instance %s due to float collision with %s "
3147 "using the same certificate and username",
3148 multi_instance_string(ex_mi, false, &gc), multi_instance_string(mi, false, &gc));
3149 multi_close_instance(m, ex_mi, false);
3150 ret = true;
3151
3152done:
3153 gc_free(&gc);
3154 return ret;
3155}
3156
3165static void
3167{
3168 struct mroute_addr real = { 0 };
3169
3170 if (mi->real.type & MR_WITH_PROTO)
3171 {
3172 real.type |= MR_WITH_PROTO;
3173 real.proto = sock->info.proto;
3174 }
3175
3176 if (!mroute_extract_openvpn_sockaddr(&real, &m->top.c2.from.dest, true))
3177 {
3178 return;
3179 }
3180
3181 if (!multi_check_dest_addr_allowed(m, mi, &real))
3182 {
3183 return;
3184 }
3185
3186 struct gc_arena gc = gc_new();
3187
3188 msg(D_MULTI_MEDIUM, "peer %" PRIu32 " (%s) floated from %s to %s",
3190 tls_common_name(mi->context.c2.tls_multi, false),
3193
3194 /* remove old address from hash table before changing address */
3195 ASSERT(hash_remove(m->hash, &mi->real));
3196
3197 /* change external network address of the remote peer */
3198 mi->real = real;
3199 generate_prefix(mi);
3200
3201 mi->context.c2.from = m->top.c2.from;
3202 mi->context.c2.to_link_addr = &mi->context.c2.from;
3203
3204 /* inherit parent link_socket and link_socket_info */
3205 mi->context.c2.link_sockets[0] = sock;
3207
3209
3210 ASSERT(hash_add(m->hash, &mi->real, mi, false));
3211
3212#ifdef ENABLE_MANAGEMENT
3213 ASSERT(hash_add(m->cid_hash, &mi->context.c2.mda_context.cid, mi, true));
3214#endif
3215
3216 gc_free(&gc);
3217}
3218
3219/*
3220 * Called when an instance should be closed due to the
3221 * reception of a soft signal.
3222 */
3223void
3225{
3226 remap_signal(&mi->context);
3227 set_prefix(mi);
3228 print_signal(mi->context.sig, "client-instance", D_MULTI_LOW);
3229 clear_prefix();
3230 multi_close_instance(m, mi, false);
3231}
3232
3233#if (defined(ENABLE_DCO) && (defined(TARGET_LINUX) || defined(TARGET_FREEBSD))) \
3234 || defined(ENABLE_MANAGEMENT)
3235static void
3236multi_signal_instance(struct multi_context *m, struct multi_instance *mi, const int sig)
3237{
3238 mi->context.sig->signal_received = sig;
3240}
3241#endif
3242
3243#if defined(ENABLE_DCO)
3244static void
3245process_incoming_del_peer(struct multi_context *m, struct multi_instance *mi, dco_context_t *dco)
3246{
3247 const char *reason = "ovpn-dco: unknown reason";
3248 switch (dco->dco_del_peer_reason)
3249 {
3251 reason = "ovpn-dco: ping expired";
3252 break;
3253
3255 reason = "ovpn-dco: transport error";
3256 break;
3257
3259 reason = "ovpn-dco: transport disconnected";
3260 break;
3261
3263 /* We assume that is ourselves. Unfortunately, sometimes these
3264 * events happen with enough delay that they can have an order of
3265 *
3266 * dco_del_peer x
3267 * [new client connecting]
3268 * dco_new_peer x
3269 * event from dco_del_peer arrives.
3270 *
3271 * if we do not ignore this we get desynced with the kernel
3272 * since we assume the peer-id is free again. The other way would
3273 * be to send a dco_del_peer again
3274 */
3275 return;
3276 }
3277
3278 /* When kernel already deleted the peer, the socket is no longer
3279 * installed, and we do not need to clean up the state in the kernel */
3280 mi->context.c2.tls_multi->dco_peer_id = -1;
3281 mi->context.sig->signal_text = reason;
3283}
3284
3285void
3287{
3288 ASSERT(dco->c->multi);
3289
3290 struct multi_context *m = dco->c->multi;
3291
3292 int peer_id = dco->dco_message_peer_id;
3293
3294 /* no peer-specific message delivered -> nothing to process.
3295 * bail out right away
3296 */
3297 if (peer_id < 0)
3298 {
3299 return;
3300 }
3301
3302 if (((uint32_t)peer_id < m->max_clients) && m->instances[peer_id])
3303 {
3304 struct multi_instance *mi = m->instances[peer_id];
3305 set_prefix(mi);
3306 if (dco->dco_message_type == OVPN_CMD_DEL_PEER)
3307 {
3308 process_incoming_del_peer(m, mi, dco);
3309 }
3310 else if (dco->dco_message_type == OVPN_CMD_FLOAT_PEER)
3311 {
3312 ASSERT(mi->context.c2.link_sockets[0]);
3314 &m->top.c2.from.dest,
3315 (struct sockaddr *)&dco->dco_float_peer_ss);
3317 CLEAR(dco->dco_float_peer_ss);
3318 }
3319 else if (dco->dco_message_type == OVPN_CMD_SWAP_KEYS)
3320 {
3322 }
3323 clear_prefix();
3324 }
3325 else
3326 {
3327 msglvl_t msglevel = D_DCO;
3328 if (dco->dco_message_type == OVPN_CMD_DEL_PEER
3329 && dco->dco_del_peer_reason == OVPN_DEL_PEER_REASON_USERSPACE)
3330 {
3331 /* we receive OVPN_CMD_DEL_PEER message with reason USERSPACE
3332 * after we kill the peer ourselves. This peer may have already
3333 * been deleted, so we end up here.
3334 * In this case, print the following debug message with DCO_DEBUG
3335 * level only to avoid polluting the standard DCO level with this
3336 * harmless event.
3337 */
3338 msglevel = D_DCO_DEBUG;
3339 }
3340 msg(msglevel,
3341 "Received DCO message for unknown peer-id: %d, "
3342 "type %d, del_peer_reason %d",
3343 peer_id, dco->dco_message_type, dco->dco_del_peer_reason);
3344 }
3345}
3346#endif /* if defined(ENABLE_DCO) */
3347
3354static void
3355multi_process_incoming_link_data(struct multi_context *m, bool floated, struct link_socket *sock)
3356{
3357 struct link_socket_info *lsi = &sock->info;
3358 const uint8_t *orig_buf;
3359
3360 /* decrypt in instance context */
3361 struct context *c = &m->pending->context;
3362
3363 orig_buf = c->c2.buf.data;
3364 if (process_incoming_link_part1(c, lsi, floated))
3365 {
3366 /* nonzero length means that we have a valid, decrypted packed */
3367 if (floated && c->c2.buf.len > 0)
3368 {
3369 multi_process_float(m, m->pending, sock);
3370 }
3371
3372 process_incoming_link_part2(c, lsi, orig_buf);
3373 }
3374
3376 {
3377 struct mroute_addr src, dest;
3378 /* extract packet source and dest addresses */
3379 unsigned int mroute_flags =
3381
3382 /* drop packet if extract failed */
3383 if (!(mroute_flags & MROUTE_EXTRACT_SUCCEEDED))
3384 {
3385 c->c2.to_tun.len = 0;
3386 }
3387 /* make sure that source address is associated with this client */
3388 else if (multi_get_instance_by_virtual_addr(m, &src, true) != m->pending)
3389 {
3390 /* IPv6 link-local address (fe80::xxx)? */
3391 if ((src.type & MR_ADDR_MASK) == MR_ADDR_IPV6
3392 && IN6_IS_ADDR_LINKLOCAL(&src.v6.addr))
3393 {
3394 /* do nothing, for now. TODO: add address learning */
3395 }
3396 else
3397 {
3398 struct gc_arena gc = gc_new();
3400 "MULTI: bad source address from client [%s], packet dropped",
3401 mroute_addr_print(&src, &gc));
3402 gc_free(&gc);
3403 }
3404 c->c2.to_tun.len = 0;
3405 }
3406 /* client-to-client communication enabled? */
3407 else if (m->enable_c2c)
3408 {
3409 /* multicast? */
3410 if (mroute_flags & MROUTE_EXTRACT_MCAST)
3411 {
3412 /* for now, treat multicast as broadcast */
3413 multi_bcast(m, &c->c2.to_tun, m->pending, 0);
3414 }
3415 else /* possible client to client routing */
3416 {
3417 ASSERT(!(mroute_flags & MROUTE_EXTRACT_BCAST));
3418 struct multi_instance *mi = multi_get_instance_by_virtual_addr(m, &dest, true);
3419
3420 /* if dest addr is a known client, route to it */
3421 if (mi)
3422 {
3423 {
3424 multi_unicast(m, &c->c2.to_tun, mi);
3426 }
3427 c->c2.to_tun.len = 0;
3428 }
3429 }
3430 }
3431 }
3432 else if (TUNNEL_TYPE(m->top.c1.tuntap) == DEV_TYPE_TAP)
3433 {
3434 uint16_t vid = 0;
3435
3436 if (m->top.options.vlan_tagging)
3437 {
3438 if (vlan_is_tagged(&c->c2.to_tun))
3439 {
3440 /* Drop VLAN-tagged frame. */
3441 msg(D_VLAN_DEBUG, "dropping incoming VLAN-tagged frame");
3442 c->c2.to_tun.len = 0;
3443 }
3444 else
3445 {
3446 vid = c->options.vlan_pvid;
3447 }
3448 }
3449 /* extract packet source and dest addresses */
3450 struct mroute_addr src, dest;
3451 /* extract packet source and dest addresses */
3452 unsigned int mroute_flags =
3454
3455 if (mroute_flags & MROUTE_EXTRACT_SUCCEEDED)
3456 {
3457 if (multi_learn_addr(m, m->pending, &src, 0) == m->pending)
3458 {
3459 /* check for broadcast */
3460 if (m->enable_c2c)
3461 {
3462 if (mroute_flags & (MROUTE_EXTRACT_BCAST | MROUTE_EXTRACT_MCAST))
3463 {
3464 multi_bcast(m, &c->c2.to_tun, m->pending, vid);
3465 }
3466 else /* try client-to-client routing */
3467 {
3468 struct multi_instance *mi = multi_get_instance_by_virtual_addr(m, &dest, false);
3469
3470 /* if dest addr is a known client, route to it */
3471 if (mi)
3472 {
3473 multi_unicast(m, &c->c2.to_tun, mi);
3475 c->c2.to_tun.len = 0;
3476 }
3477 }
3478 }
3479 }
3480 else
3481 {
3482 struct gc_arena gc = gc_new();
3484 "MULTI: bad source address from client [%s], packet dropped",
3485 mroute_addr_print(&src, &gc));
3486 c->c2.to_tun.len = 0;
3487 gc_free(&gc);
3488 }
3489 }
3490 else
3491 {
3492 c->c2.to_tun.len = 0;
3493 }
3494 }
3495}
3496
3497/*
3498 * Process packets in the TCP/UDP socket -> TUN/TAP interface direction,
3499 * i.e. client -> server direction.
3500 */
3501bool
3503 const unsigned int mpp_flags, struct link_socket *sock)
3504{
3505 struct context *c;
3506 bool ret = true;
3507 bool floated = false;
3508
3509 if (m->pending)
3510 {
3511 return true;
3512 }
3513
3514 if (!instance)
3515 {
3516#ifdef MULTI_DEBUG_EVENT_LOOP
3517 printf("TCP/UDP -> TUN [%d]\n", BLEN(&m->top.c2.buf));
3518#endif
3519 multi_set_pending(m, multi_get_create_instance_udp(m, &floated, sock));
3520 }
3521 else
3522 {
3523 multi_set_pending(m, instance);
3524 }
3525
3526 if (!m->pending)
3527 {
3528 return true;
3529 }
3530 set_prefix(m->pending);
3531
3532 /* get instance context */
3533 c = &m->pending->context;
3534
3535 if (!instance)
3536 {
3537 /* transfer packet pointer from top-level context buffer to instance */
3538 c->c2.buf = m->top.c2.buf;
3539
3540 /* transfer from-addr from top-level context buffer to instance */
3541 if (!floated)
3542 {
3543 c->c2.from = m->top.c2.from;
3544 }
3545 }
3546
3547 if (BLEN(&c->c2.buf) > 0)
3548 {
3549 multi_process_incoming_link_data(m, floated, sock);
3550 }
3551
3552 /* postprocess and set wakeup */
3553 ret = multi_process_post(m, m->pending, mpp_flags);
3554
3555 clear_prefix();
3556
3557 return ret;
3558}
3559
3560/*
3561 * Process packets in the TUN/TAP interface -> TCP/UDP socket direction,
3562 * i.e. server -> client direction.
3563 */
3564bool
3565multi_process_incoming_tun(struct multi_context *m, const unsigned int mpp_flags)
3566{
3567 bool ret = true;
3568
3569 if (BLEN(&m->top.c2.buf) > 0)
3570 {
3571 unsigned int mroute_flags;
3572 struct mroute_addr src = { 0 }, dest = { 0 };
3573 const int dev_type = TUNNEL_TYPE(m->top.c1.tuntap);
3574 int16_t vid = 0;
3575
3576#ifdef MULTI_DEBUG_EVENT_LOOP
3577 printf("TUN -> TCP/UDP [%d]\n", BLEN(&m->top.c2.buf));
3578#endif
3579
3580 if (m->pending)
3581 {
3582 return true;
3583 }
3584
3585 if (dev_type == DEV_TYPE_TAP && m->top.options.vlan_tagging)
3586 {
3587 vid = vlan_decapsulate(&m->top, &m->top.c2.buf);
3588 if (vid < 0)
3589 {
3590 return false;
3591 }
3592 }
3593
3594 /*
3595 * Route an incoming tun/tap packet to
3596 * the appropriate multi_instance object.
3597 */
3598 mroute_flags = mroute_extract_addr_from_packet(&src, &dest, vid, &m->top.c2.buf, dev_type);
3599
3600 if (mroute_flags & MROUTE_EXTRACT_SUCCEEDED)
3601 {
3602 struct context *c;
3603
3604 /* broadcast or multicast dest addr? */
3605 if (mroute_flags & (MROUTE_EXTRACT_BCAST | MROUTE_EXTRACT_MCAST))
3606 {
3607 /* for now, treat multicast as broadcast */
3608 multi_bcast(m, &m->top.c2.buf, NULL, vid);
3609 }
3610 else
3611 {
3613 m, multi_get_instance_by_virtual_addr(m, &dest, dev_type == DEV_TYPE_TUN));
3614
3615 if (m->pending)
3616 {
3617 /* get instance context */
3618 c = &m->pending->context;
3619
3620 set_prefix(m->pending);
3621
3622 {
3624 {
3625 /* transfer packet pointer from top-level context buffer to instance */
3626 c->c2.buf = m->top.c2.buf;
3627 }
3628 else
3629 {
3630 /* drop packet */
3632 "MULTI: packet dropped due to output saturation (multi_process_incoming_tun)");
3633 buf_reset_len(&c->c2.buf);
3634 }
3635 }
3636
3637 /* encrypt in instance context */
3639
3640 /* postprocess and set wakeup */
3641 ret = multi_process_post(m, m->pending, mpp_flags);
3642
3643 clear_prefix();
3644 }
3645 }
3646 }
3647 }
3648 return ret;
3649}
3650
3651/*
3652 * Process a possible client-to-client/bcast/mcast message in the
3653 * queue.
3654 */
3655struct multi_instance *
3657{
3658 struct mbuf_item item;
3659
3660 if (mbuf_extract_item(ms, &item)) /* cleartext IP packet */
3661 {
3662 unsigned int pip_flags = PIPV4_PASSTOS | PIPV6_ICMP_NOHOST_SERVER;
3663
3664 set_prefix(item.instance);
3665 item.instance->context.c2.buf = item.buffer->buf;
3666 if (item.buffer->flags
3667 & MF_UNICAST) /* --mssfix doesn't make sense for broadcast or multicast */
3668 {
3669 pip_flags |= PIP_MSSFIX;
3670 }
3671 process_ip_header(&item.instance->context, pip_flags, &item.instance->context.c2.buf,
3672 item.instance->context.c2.link_sockets[0]);
3673 encrypt_sign(&item.instance->context, true);
3674 mbuf_free_buf(item.buffer);
3675
3676 dmsg(D_MULTI_DEBUG, "MULTI: C2C/MCAST/BCAST");
3677
3678 clear_prefix();
3679 return item.instance;
3680 }
3681 else
3682 {
3683 return NULL;
3684 }
3685}
3686
3687/*
3688 * Called when an I/O wait times out. Usually means that a particular
3689 * client instance object needs timer-based service.
3690 */
3691bool
3692multi_process_timeout(struct multi_context *m, const unsigned int mpp_flags)
3693{
3694 bool ret = true;
3695
3696#ifdef MULTI_DEBUG_EVENT_LOOP
3697 printf("%s -> TIMEOUT\n", id(m->earliest_wakeup));
3698#endif
3699
3700 /* instance marked for wakeup? */
3701 if (m->earliest_wakeup)
3702 {
3704 {
3708 }
3709 else
3710 {
3712 ret = multi_process_post(m, m->earliest_wakeup, mpp_flags);
3713 clear_prefix();
3714 }
3715 m->earliest_wakeup = NULL;
3716 }
3717 return ret;
3718}
3719
3720/*
3721 * Drop a TUN/TAP outgoing packet..
3722 */
3723void
3724multi_process_drop_outgoing_tun(struct multi_context *m, const unsigned int mpp_flags)
3725{
3726 struct multi_instance *mi = m->pending;
3727
3728 ASSERT(mi);
3729
3730 set_prefix(mi);
3731
3732 msg(D_MULTI_ERRORS, "MULTI: Outgoing TUN queue full, dropped packet len=%d",
3733 mi->context.c2.to_tun.len);
3734
3735 buf_reset(&mi->context.c2.to_tun);
3736
3737 multi_process_post(m, mi, mpp_flags);
3738 clear_prefix();
3739}
3740
3741/*
3742 * Per-client route quota management
3743 */
3744
3745void
3747{
3748 struct gc_arena gc = gc_new();
3750 "MULTI ROUTE: route quota (%d) exceeded for %s (see --max-routes-per-client option)",
3752 gc_free(&gc);
3753}
3754
3755#ifdef ENABLE_DEBUG
3756/*
3757 * Flood clients with random packets
3758 */
3759static void
3760gremlin_flood_clients(struct multi_context *m)
3761{
3762 const int level = GREMLIN_PACKET_FLOOD_LEVEL(m->top.options.gremlin);
3763 if (level)
3764 {
3765 struct gc_arena gc = gc_new();
3766 struct buffer buf = alloc_buf_gc(BUF_SIZE(&m->top.c2.frame), &gc);
3767 struct packet_flood_parms parm = get_packet_flood_parms(level);
3768 int i;
3769
3770 ASSERT(buf_init(&buf, m->top.c2.frame.buf.headroom));
3771 parm.packet_size = min_int(parm.packet_size, m->top.c2.frame.buf.payload_size);
3772
3773 msg(D_GREMLIN, "GREMLIN_FLOOD_CLIENTS: flooding clients with %d packets of size %d",
3774 parm.n_packets, parm.packet_size);
3775
3776 for (i = 0; i < parm.packet_size; ++i)
3777 {
3778 ASSERT(buf_write_u8(&buf, (uint8_t)(get_random() & 0xFF)));
3779 }
3780
3781 for (i = 0; i < parm.n_packets; ++i)
3782 {
3783 multi_bcast(m, &buf, NULL, 0);
3784 }
3785
3786 gc_free(&gc);
3787 }
3788}
3789#endif /* ifdef ENABLE_DEBUG */
3790
3791static bool
3793{
3794 struct timeval null;
3795 CLEAR(null);
3797}
3798
3799/*
3800 * Process timers in the top-level context
3801 */
3802void
3804{
3805 /* possibly reap instances/routes in vhash */
3807
3808 /* possibly print to status log */
3809 if (m->top.c1.status_output)
3810 {
3812 {
3814 }
3815 }
3816
3817 /* possibly flush ifconfig-pool file */
3819
3820#ifdef ENABLE_DEBUG
3821 gremlin_flood_clients(m);
3822#endif
3823
3824 /* Should we check for stale routes? */
3826 {
3828 }
3829}
3830
3831static void
3833{
3834 inherit_context_top(&top->multi->top, top);
3836}
3837
3838static void
3844
3845static bool
3847{
3848 return (sig == SIGUSR1 || sig == SIGTERM || sig == SIGHUP || sig == SIGINT);
3849}
3850
3851static void
3853{
3854 /* tell all clients to restart */
3855 for (uint32_t i = 0; i <= m->max_peerid; i++)
3856 {
3857 struct multi_instance *mi = m->instances[i];
3858 if (mi && !mi->halt && proto_is_dgram(mi->context.c2.link_sockets[0]->info.proto))
3859 {
3860 send_control_channel_string(&mi->context, next_server ? "RESTART,[N]" : "RESTART",
3861 D_PUSH);
3863 }
3864 }
3865
3866 /* reschedule signal */
3868 struct timeval tv = { .tv_sec = 2, .tv_usec = 0 };
3870
3872
3876
3877 signal_reset(m->top.sig, 0);
3878}
3879
3880/*
3881 * Return true if event loop should break,
3882 * false if it should continue.
3883 */
3884bool
3886{
3887 if (signal_reset(m->top.sig, SIGUSR2) == SIGUSR2)
3888 {
3889 struct status_output *so = status_open(NULL, 0, M_INFO, NULL, 0);
3891 status_close(so);
3892 return false;
3893 }
3897 {
3899 return false;
3900 }
3901 return true;
3902}
3903
3904/*
3905 * Management subsystem callbacks
3906 */
3907#ifdef ENABLE_MANAGEMENT
3908
3909static void
3910management_callback_status(void *arg, const int version, struct status_output *so)
3911{
3912 struct multi_context *m = (struct multi_context *)arg;
3913
3914 if (!version)
3915 {
3917 }
3918 else
3919 {
3920 multi_print_status(m, so, version);
3921 }
3922}
3923
3924static int
3926{
3927 const struct multi_context *m = (struct multi_context *)arg;
3928 return m->n_clients;
3929}
3930
3931static int
3932management_callback_kill_by_cn(void *arg, const char *del_cn)
3933{
3934 struct multi_context *m = (struct multi_context *)arg;
3935 int count = 0;
3936
3937 for (uint32_t i = 0; i <= m->max_peerid; i++)
3938 {
3939 struct multi_instance *mi = m->instances[i];
3940 if (mi && !mi->halt)
3941 {
3942 const char *cn = tls_common_name(mi->context.c2.tls_multi, false);
3943 if (cn && !strcmp(cn, del_cn))
3944 {
3946 ++count;
3947 }
3948 }
3949 }
3950 return count;
3951}
3952
3953static int
3954management_callback_kill_by_addr(void *arg, const in_addr_t addr, const uint16_t port, const uint8_t proto)
3955{
3956 struct multi_context *m = (struct multi_context *)arg;
3957 struct openvpn_sockaddr saddr;
3958 struct mroute_addr maddr;
3959 int count = 0;
3960
3961 CLEAR(saddr);
3962 saddr.addr.in4.sin_family = AF_INET;
3963 saddr.addr.in4.sin_addr.s_addr = htonl(addr);
3964 saddr.addr.in4.sin_port = htons(port);
3965 maddr.proto = proto;
3966 if (mroute_extract_openvpn_sockaddr(&maddr, &saddr, true))
3967 {
3968 for (uint32_t i = 0; i <= m->max_peerid; i++)
3969 {
3970 struct multi_instance *mi = m->instances[i];
3971 if (mi && !mi->halt && mroute_addr_equal(&maddr, &mi->real))
3972 {
3974 ++count;
3975 }
3976 }
3977 }
3978 return count;
3979}
3980
3981static void
3983{
3984 struct multi_context *m = (struct multi_context *)arg;
3985 if (m->multi_io)
3986 {
3988 }
3989}
3990
3991struct multi_instance *
3992lookup_by_cid(struct multi_context *m, const unsigned long cid)
3993{
3994 if (m)
3995 {
3996 struct multi_instance *mi = (struct multi_instance *)hash_lookup(m->cid_hash, &cid);
3997 if (mi && !mi->halt)
3998 {
3999 return mi;
4000 }
4001 }
4002 return NULL;
4003}
4004
4005static bool
4006management_kill_by_cid(void *arg, const unsigned long cid, const char *kill_msg)
4007{
4008 struct multi_context *m = (struct multi_context *)arg;
4009 struct multi_instance *mi = lookup_by_cid(m, cid);
4010 if (mi)
4011 {
4012 send_restart(&mi->context, kill_msg); /* was: multi_signal_instance (m, mi, SIGTERM); */
4014 return true;
4015 }
4016 else
4017 {
4018 return false;
4019 }
4020}
4021
4022static struct tls_session *
4024 const unsigned int mda_key_id)
4025{
4026 if (multi->session[TM_INITIAL].key[KS_PRIMARY].mda_key_id == mda_key_id)
4027 {
4028 return &multi->session[TM_INITIAL];
4029 }
4030 else if (multi->session[TM_ACTIVE].key[KS_PRIMARY].mda_key_id == mda_key_id)
4031 {
4032 return &multi->session[TM_ACTIVE];
4033 }
4034 else
4035 {
4036 return NULL;
4037 }
4038}
4039
4040static bool
4041management_client_pending_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id,
4042 const char *extra, unsigned int timeout)
4043{
4044 struct multi_context *m = (struct multi_context *)arg;
4045 struct multi_instance *mi = lookup_by_cid(m, cid);
4046
4047 if (mi)
4048 {
4049 struct tls_multi *multi = mi->context.c2.tls_multi;
4050 struct tls_session *session = lookup_session_by_mda_key_id(multi, mda_key_id);
4051
4052 if (!session)
4053 {
4054 return false;
4055 }
4056
4057 /* sends INFO_PRE and AUTH_PENDING messages to client */
4058 bool ret = send_auth_pending_messages(multi, session, extra, timeout);
4061 return ret;
4062 }
4063 return false;
4064}
4065
4066
4067static bool
4068management_client_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id,
4069 const bool auth, const char *reason, const char *client_reason,
4070 struct buffer_list *cc_config) /* ownership transferred */
4071{
4072 struct multi_context *m = (struct multi_context *)arg;
4073 struct multi_instance *mi = lookup_by_cid(m, cid);
4074 bool cc_config_owned = true;
4075 bool ret = false;
4076
4077 if (mi)
4078 {
4079 ret = tls_authenticate_key(mi->context.c2.tls_multi, mda_key_id, auth, client_reason);
4080 if (ret)
4081 {
4082 if (auth)
4083 {
4085 {
4087 cc_config_owned = false;
4088 }
4089 }
4090 else if (reason)
4091 {
4092 msg(D_MULTI_LOW, "MULTI: connection rejected: %s, CLI:%s", reason,
4093 np(client_reason));
4094 }
4095 }
4096 }
4097 if (cc_config_owned && cc_config)
4098 {
4100 }
4101 return ret;
4102}
4103
4104static char *
4105management_get_peer_info(void *arg, const unsigned long cid)
4106{
4107 struct multi_context *m = (struct multi_context *)arg;
4108 struct multi_instance *mi = lookup_by_cid(m, cid);
4109 char *ret = NULL;
4110
4111 if (mi)
4112 {
4113 ret = mi->context.c2.tls_multi->peer_info;
4114 }
4115
4116 return ret;
4117}
4118
4119#endif /* ifdef ENABLE_MANAGEMENT */
4120
4121
4122void
4148
4149void
4151{
4152 /* max_clients must be less then max peer-id value */
4154
4155 for (uint32_t i = 0; i < m->max_clients; ++i)
4156 {
4157 if (!m->instances[i])
4158 {
4159 mi->context.c2.tls_multi->rx_peer_id = i;
4160 m->instances[i] = mi;
4161 break;
4162 }
4163 }
4164
4165 /* should not really end up here, since multi_create_instance returns null
4166 * if amount of clients exceeds max_clients and this method would then
4167 * also not have been called */
4169
4171 {
4173 }
4174}
4175
4186static void
4187multi_get_timeout(struct multi_context *multi, struct timeval *timeval)
4188{
4189 multi_get_timeout_instance(multi, timeval);
4190
4191#ifdef ENABLE_MANAGEMENT
4192 if (management)
4193 {
4194 management_check_bytecount_server(multi, timeval);
4195 }
4196#endif /* ENABLE_MANAGEMENT */
4197}
4198
4199/**************************************************************************/
4206static void
4208{
4209 int status;
4210
4211 while (true)
4212 {
4213 /* wait on tun/socket list */
4214 multi_get_timeout(multi, &multi->top.c2.timeval);
4215 status = multi_io_wait(multi);
4216 MULTI_CHECK_SIG(multi);
4217
4218 /* check on status of coarse timers */
4220
4221 /* timeout? */
4222 if (status > 0)
4223 {
4224 /* process the I/O which triggered select */
4225 multi_io_process_io(multi);
4226 }
4227 else if (status == 0)
4228 {
4229 multi_io_action(multi, NULL, TA_TIMEOUT, false);
4230 }
4231
4232 MULTI_CHECK_SIG(multi);
4233 }
4234}
4235
4236/*
4237 * Top level event loop.
4238 */
4239void
4241{
4242 ASSERT(top->options.mode == MODE_SERVER);
4243
4244 struct multi_context multi;
4245
4246 top->mode = CM_TOP;
4247 // cppcheck-suppress autoVariables ; yes, we know this is dangerous
4248 top->multi = &multi;
4250
4251 /* initialize top-tunnel instance */
4253 if (IS_SIG(top))
4254 {
4255 return;
4256 }
4257
4258 /* initialize global multi_context object */
4259 multi_init(top);
4260
4261 /* initialize our cloned top object */
4263
4264 /* initialize management interface */
4266
4267 /* finished with initialization */
4268 initialization_sequence_completed(top, ISC_SERVER); /* --mode server --proto tcp-server */
4269
4270#ifdef ENABLE_ASYNC_PUSH
4271 multi.top.c2.inotify_fd = inotify_init();
4272 if (multi.top.c2.inotify_fd < 0)
4273 {
4274 msg(D_MULTI_ERRORS | M_ERRNO, "MULTI: inotify_init error");
4275 }
4276#endif
4277
4278 tunnel_server_loop(&multi);
4279
4280#ifdef ENABLE_ASYNC_PUSH
4281 msg(D_LOW, "%s: close multi.top.c2.inotify_fd (%d)",
4282 __func__, multi.top.c2.inotify_fd);
4283 close(multi.top.c2.inotify_fd);
4284#endif
4285
4286 /* shut down management interface */
4288
4289 /* save ifconfig-pool */
4290 multi_ifconfig_pool_persist(&multi, true);
4291
4292 /* tear down tunnel instance (unless --persist-tun) */
4293 multi_uninit(&multi);
4294 multi_top_free(&multi);
4296}
4297
4298/* Searches for the address and deletes it if it is owned by the multi_instance */
4299static void
4300multi_unlearn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr)
4301{
4302 struct hash_element *he;
4303 const uint64_t hv = hash_value(m->vhash, addr);
4304 struct hash_bucket *bucket = hash_bucket(m->vhash, hv);
4305 struct multi_route *r = NULL;
4306
4307 /* if route currently exists, get the instance which owns it */
4308 he = hash_lookup_fast(m->vhash, bucket, addr, hv);
4309 if (he)
4310 {
4311 r = (struct multi_route *)he->value;
4312 }
4313
4314 /* if the route does not exist or exists but is not owned by the current instance, return */
4315 if (!r || r->instance != mi)
4316 {
4317 return;
4318 }
4319
4320 struct gc_arena gc = gc_new();
4321 msg(D_MULTI_LOW, "MULTI: Unlearn: %s -> %s", mroute_addr_print(&r->addr, &gc), multi_instance_string(mi, false, &gc));
4322 learn_address_script(m, NULL, "delete", &r->addr);
4324 multi_route_del(r);
4325
4326 gc_free(&gc);
4327}
4328
4334static void
4336{
4337 struct mroute_addr addr;
4338 CLEAR(addr);
4339
4340 addr.type = MR_ADDR_IPV4;
4341 addr.len = 4;
4342 addr.v4.addr = a;
4343
4344 multi_unlearn_addr(m, mi, &addr);
4345}
4346
4352static void
4353multi_unlearn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6)
4354{
4355 struct mroute_addr addr;
4356 CLEAR(addr);
4357
4358 addr.type = MR_ADDR_IPV6;
4359 addr.len = 16;
4360 addr.v6.addr = a6;
4361
4362 multi_unlearn_addr(m, mi, &addr);
4363}
4364
4365/* Function to unlearn previous ifconfig of a client in the server multi_context after a PUSH_UPDATE */
4366void
4368{
4369 in_addr_t old_addr = 0;
4370 old_addr = htonl(mi->context.c2.push_ifconfig_local);
4371 multi_unlearn_in_addr_t(m, mi, old_addr);
4372 mi->context.c2.push_ifconfig_defined = false;
4374 mi->reporting_addr = 0;
4375}
4376
4377/* Function to unlearn previous ifconfig-ipv6 of a client in the server multi_context after a PUSH_UPDATE */
4378void
4380{
4381 struct in6_addr old_addr6;
4382 CLEAR(old_addr6);
4383 old_addr6 = mi->context.c2.push_ifconfig_ipv6_local;
4384 multi_unlearn_in6_addr(m, mi, old_addr6);
4388}
4389
4400void
4401update_vhash(struct multi_context *m, struct multi_instance *mi, const char *new_ip, const char *new_ipv6)
4402{
4403 if (new_ip)
4404 {
4405 /* Remove old IP */
4407 {
4408 unlearn_ifconfig(m, mi);
4409 }
4410
4411 /* Add new IP */
4412 struct in_addr new_addr;
4413 CLEAR(new_addr);
4414 if (inet_pton(AF_INET, new_ip, &new_addr) == 1
4415 && multi_learn_in_addr_t(m, mi, ntohl(new_addr.s_addr), -1, true))
4416 {
4417 mi->context.c2.push_ifconfig_defined = true;
4418 mi->context.c2.push_ifconfig_local = ntohl(new_addr.s_addr);
4419 /* set our client's VPN endpoint for status reporting purposes */
4421 }
4422 }
4423
4424 if (new_ipv6)
4425 {
4426 /* Remove old IPv6 */
4428 {
4429 unlearn_ifconfig_ipv6(m, mi);
4430 }
4431
4432 /* Add new IPv6 */
4433 struct in6_addr new_addr6;
4434 CLEAR(new_addr6);
4435 if (inet_pton(AF_INET6, new_ipv6, &new_addr6) == 1
4436 && multi_learn_in6_addr(m, mi, new_addr6, -1, true))
4437 {
4439 mi->context.c2.push_ifconfig_ipv6_local = new_addr6;
4440 /* set our client's VPN endpoint for status reporting purposes */
4442 }
4443 }
4444}
4445
4446bool
4448{
4449 in_addr_t local_addr, local_netmask;
4450
4452 {
4453 /* If we do not have a local address, we just return false as
4454 * this check doesn't make sense. */
4455 return false;
4456 }
4457
4458 /* if it falls into the network defined by ifconfig_local we assume
4459 * it is already known to DCO and only install "extra" iroutes */
4460 inet_pton(AF_INET, o->ifconfig_local, &local_addr);
4461 inet_pton(AF_INET, o->ifconfig_remote_netmask, &local_netmask);
4462
4463 return (local_addr & local_netmask) != (dest & local_netmask);
4464}
4465
4466bool
4467multi_check_push_ifconfig_ipv6_extra_route(const struct options *o, const struct in6_addr *dest)
4468{
4470 {
4471 /* If we do not have a local address, we just return false as
4472 * this check doesn't make sense. */
4473 return false;
4474 }
4475
4476 /* if it falls into the network defined by ifconfig_local we assume
4477 * it is already known to DCO and only install "extra" iroutes */
4478 struct in6_addr ifconfig_local;
4479 if (inet_pton(AF_INET6, o->ifconfig_ipv6_local, &ifconfig_local) != 1)
4480 {
4481 return false;
4482 }
4483
4484 return (!ipv6_net_contains_host(&ifconfig_local, o->ifconfig_ipv6_netbits,
4485 dest));
4486}
void argv_parse_cmd(struct argv *argres, const char *cmdstr)
Parses a command string, tokenizes it and puts each element into a separate struct argv argument slot...
Definition argv.c:481
void argv_free(struct argv *a)
Frees all memory allocations allocated by the struct argv related functions.
Definition argv.c:101
bool argv_printf(struct argv *argres, const char *format,...)
printf() variant which populates a struct argv.
Definition argv.c:438
bool argv_printf_cat(struct argv *argres, const char *format,...)
printf() inspired argv concatenation.
Definition argv.c:462
struct argv argv_new(void)
Allocates a new struct argv and ensures it is initialised.
Definition argv.c:87
void generate_auth_token(const struct user_pass *up, struct tls_multi *multi)
Generate an auth token based on username and timestamp.
Definition auth_token.c:179
bool buf_printf(struct buffer *buf, const char *format,...)
printf-style append to a buffer with overflow check.
Definition buffer.c:226
void buffer_list_free(struct buffer_list *ol)
Frees a buffer list and all the buffers in it.
Definition buffer.c:1165
struct buffer alloc_buf_gc(size_t size, struct gc_arena *gc)
Allocate a buffer of the given size under garbage collection.
Definition buffer.c:77
char * string_alloc(const char *str, struct gc_arena *gc)
Duplicate a string, allocating memory under garbage collection.
Definition buffer.c:616
#define ALLOC_OBJ(dptr, type)
Allocate memory for a single object of the given type.
Definition buffer.h:2027
#define BSTR(buf)
Return the buffer content pointer cast to char *.
Definition buffer.h:157
static void buf_reset(struct buffer *buf)
Reset a buffer to an undefined (unallocated) state.
Definition buffer.h:599
static bool buf_write_u8(struct buffer *dest, uint8_t data)
Append a uint8_t to a buffer.
Definition buffer.h:1306
#define BLEN(buf)
Return the length of the buffer content in bytes.
Definition buffer.h:151
static void buf_reset_len(struct buffer *buf)
Reset the length and offset of a buffer to zero.
Definition buffer.h:616
static void strncpynt(char *dest, const char *src, size_t maxlen)
Like strncpy() but always null-terminates the destination.
Definition buffer.h:710
static void gc_free(struct gc_arena *a)
Free all allocations in a garbage collection arena.
Definition buffer.h:1976
#define ALLOC_OBJ_CLEAR(dptr, type)
Allocate and zero-initialise memory for a single object of the given type.
Definition buffer.h:2038
#define buf_init(buf, offset)
Definition buffer.h:364
static struct gc_arena gc_new(void)
Allocate and return a new, empty garbage collection arena.
Definition buffer.h:1960
#define CCD_DEFAULT
Definition common.h:63
#define counter_format
Definition common.h:32
bool check_compression_settings_valid(struct compress_options *info, msglvl_t msglevel)
Checks if the compression settings are valid.
Definition comp.c:162
#define COMP_ALG_STUB
support compression command byte and framing without actual compression
Definition comp.h:56
#define COMP_F_MIGRATE
push stub-v2 or comp-lzo no when we see a client with comp-lzo in occ
Definition comp.h:47
const char * translate_cipher_name_to_openvpn(const char *cipher_name)
Translate a crypto library cipher name to an OpenVPN cipher name.
Definition crypto.c:1809
int64_t get_random(void)
an analogue to the random() function, but use prng_bytes and also int64_t instead of long to avoid LL...
Definition crypto.c:1735
#define CO_USE_TLS_KEY_MATERIAL_EXPORT
Bit-flag indicating that data channel key derivation is done using TLS keying material export [RFC570...
Definition crypto.h:359
#define CO_USE_DYNAMIC_TLS_CRYPT
Bit-flag indicating that renegotiations are using tls-crypt with a TLS-EKM derived key.
Definition crypto.h:375
#define CO_EPOCH_DATA_KEY_FORMAT
Bit-flag indicating the epoch the data format.
Definition crypto.h:379
#define CO_USE_CC_EXIT_NOTIFY
Bit-flag indicating that explicit exit notifies should be sent via the control channel instead of usi...
Definition crypto.h:371
Data Channel Cryptography SSL library-specific backend interface.
bool cipher_kt_mode_aead(const char *ciphername)
Check if the supplied cipher is a supported AEAD mode cipher.
static int dco_get_peer_stats_multi(dco_context_t *dco, const bool raise_sigusr1_on_err)
Definition dco.h:369
static void dco_delete_iroutes(openvpn_net_ctx_t *net_ctx, const struct context *c)
Definition dco.h:364
static void dco_install_iroute(struct multi_context *m, struct multi_instance *mi, struct mroute_addr *addr)
Definition dco.h:359
static bool dco_check_option(msglvl_t msglevel, const struct options *o)
Definition dco.h:274
void * dco_context_t
Definition dco.h:259
static int dco_multi_add_new_peer(struct multi_context *m, struct multi_instance *mi)
Definition dco.h:353
void setenv_counter(struct env_set *es, const char *name, counter_type value)
Definition env_set.c:283
void setenv_int(struct env_set *es, const char *name, int value)
Definition env_set.c:291
void setenv_str(struct env_set *es, const char *name, const char *value)
Definition env_set.c:307
struct env_set * env_set_create(struct gc_arena *gc)
Definition env_set.c:156
void setenv_long_long(struct env_set *es, const char *name, long long value)
Definition env_set.c:299
void setenv_del(struct env_set *es, const char *name)
Definition env_set.c:352
#define D_PUSH
Definition errlevel.h:82
#define D_MULTI_ERRORS
Definition errlevel.h:64
#define D_VLAN_DEBUG
Definition errlevel.h:153
#define D_IMPORT_ERRORS
Definition errlevel.h:63
#define D_ROUTE_QUOTA
Definition errlevel.h:89
#define D_MULTI_MEDIUM
Definition errlevel.h:101
#define D_DCO
Definition errlevel.h:93
#define D_MULTI_DEBUG
Definition errlevel.h:126
#define D_MULTI_DROPPED
Definition errlevel.h:100
#define D_DCO_DEBUG
Definition errlevel.h:117
#define D_MULTI_LOW
Definition errlevel.h:85
#define D_TLS_ERRORS
Definition errlevel.h:58
#define D_LOW
Definition errlevel.h:96
#define M_INFO
Definition errlevel.h:54
#define D_GREMLIN
Definition errlevel.h:77
const struct rw_handle * event_t
Definition event.h:89
@ EVENT_ARG_MULTI_INSTANCE
Definition event.h:134
void reschedule_multi_process(struct context *c)
Reschedule tls_multi_process.
Definition forward.c:397
bool send_control_channel_string(struct context *c, const char *str, msglvl_t msglevel)
Definition forward.c:404
void pre_select(struct context *c)
Definition forward.c:1988
void process_ip_header(struct context *c, unsigned int flags, struct buffer *buf, struct link_socket *sock)
Definition forward.c:1685
void extract_dco_float_peer_addr(const sa_family_t socket_family, struct openvpn_sockaddr *out_osaddr, const struct sockaddr *float_sa)
Transfers float_sa data extracted from an incoming DCO PEER_FLOAT_NTF to out_osaddr for later process...
Definition forward.c:1234
Interface functions to the internal and external multiplexers.
#define PIP_MSSFIX
Definition forward.h:338
static void register_activity(struct context *c, const int64_t size)
Definition forward.h:365
#define PIPV6_ICMP_NOHOST_SERVER
Definition forward.h:343
static struct link_socket_info * get_link_socket_info(struct context *c)
Definition forward.h:352
#define ANY_OUT(c)
Definition forward.h:39
#define PIPV4_PASSTOS
Definition forward.h:337
#define TM_INITIAL
As yet un-trusted tls_session \ being negotiated.
Definition ssl_common.h:545
#define KS_PRIMARY
Primary key state index.
Definition ssl_common.h:464
#define TM_ACTIVE
Active tls_session.
Definition ssl_common.h:544
void encrypt_sign(struct context *c, bool comp_frag)
Process a data channel packet that will be sent through a VPN tunnel.
Definition forward.c:644
void tunnel_server(struct context *top)
Main event loop for OpenVPN in server mode.
Definition multi.c:4240
static void tunnel_server_loop(struct multi_context *multi)
Main event loop for OpenVPN in point-to-multipoint server mode.
Definition multi.c:4207
bool process_incoming_link_part1(struct context *c, struct link_socket_info *lsi, bool floated)
Starts processing a packet read from the external network interface.
Definition forward.c:1008
void process_incoming_link_part2(struct context *c, struct link_socket_info *lsi, const uint8_t *orig_buf)
Continues processing a packet read from the external network interface.
Definition forward.c:1141
bool multi_process_incoming_link(struct multi_context *m, struct multi_instance *instance, const unsigned int mpp_flags, struct link_socket *sock)
Demultiplex and process a packet received over the external network interface.
Definition multi.c:3502
struct multi_instance * multi_get_create_instance_udp(struct multi_context *m, bool *floated, struct link_socket *sock)
Get, and if necessary create, the multi_instance associated with a packet's source address.
Definition mudp.c:397
void process_incoming_tun(struct context *c, struct link_socket *out_sock)
Process a packet read from the virtual tun/tap network interface.
Definition forward.c:1500
bool multi_process_incoming_tun(struct multi_context *m, const unsigned int mpp_flags)
Determine the destination VPN tunnel of a packet received over the virtual tun/tap network interface ...
Definition multi.c:3565
void uninit_management_callback(void)
Definition init.c:4398
void initialization_sequence_completed(struct context *c, const unsigned int flags)
Definition init.c:1514
void close_instance(struct context *c)
Definition init.c:4732
void inherit_context_top(struct context *dest, const struct context *src)
Definition init.c:4893
void free_context_buffers(struct context_buffers *b)
Definition init.c:3696
void init_instance_handle_signals(struct context *c, const struct env_set *env, const unsigned int flags)
Definition init.c:4710
void inherit_context_child(struct context *dest, const struct context *src, struct link_socket *sock)
Definition init.c:4805
void context_clear_2(struct context *c)
Definition init.c:89
void close_context(struct context *c, int sig, unsigned int flags)
Definition init.c:4939
bool do_deferred_options(struct context *c, const uint64_t found, const bool is_update)
Definition init.c:2573
struct context_buffers * init_context_buffers(const struct frame *frame)
Definition init.c:3671
void management_show_net_callback(void *arg, const msglvl_t msglevel)
Definition init.c:4248
#define CC_GC_FREE
Definition init.h:109
#define CC_HARD_USR1_TO_HUP
Definition init.h:111
#define ISC_SERVER
Definition init.h:121
static unsigned int constrain_uint(unsigned int x, unsigned int min, unsigned int max)
Definition integer.h:139
static int min_int(int x, int y)
Definition integer.h:105
static SERVICE_STATUS status
Definition interactive.c:52
@ route
Definition interactive.c:86
@ read
bool event_timeout_trigger(struct event_timeout *et, struct timeval *tv, const int et_const_retry)
This is the principal function for testing and triggering recurring timers.
Definition interval.c:42
#define ETT_DEFAULT
Definition interval.h:222
static void event_timeout_init(struct event_timeout *et, interval_t n, const time_t last)
Initialises a timer struct.
Definition interval.h:172
void hash_iterator_free(struct hash_iterator *hi)
Definition list.c:272
struct hash_element * hash_iterator_next(struct hash_iterator *hi)
Definition list.c:278
void hash_iterator_delete_element(struct hash_iterator *hi)
Definition list.c:310
void hash_iterator_init(struct hash *hash, struct hash_iterator *hi)
Definition list.c:236
struct hash * hash_init(const uint32_t n_buckets, uint64_t(*hash_function)(const void *key, const uint8_t hash_key[HASH_KEY_LEN]), bool(*compare_function)(const void *key1, const void *key2))
Definition list.c:36
void hash_free(struct hash *hash)
Definition list.c:62
struct hash_element * hash_lookup_fast(struct hash *hash, struct hash_bucket *bucket, const void *key, uint64_t hv)
Definition list.c:81
bool hash_add(struct hash *hash, const void *key, void *value, bool replace)
Definition list.c:139
void hash_remove_by_value(struct hash *hash, void *value)
Definition list.c:167
void hash_iterator_init_range(struct hash *hash, struct hash_iterator *hi, uint32_t start_bucket, uint32_t end_bucket)
Definition list.c:215
static bool hash_remove(struct hash *hash, const void *key)
Definition list.h:164
static void * hash_lookup(struct hash *hash, const void *key)
Definition list.h:131
#define HASH_KEY_LEN
Definition list.h:53
static uint32_t hash_n_elements(const struct hash *hash)
Definition list.h:113
static uint32_t hash_n_buckets(const struct hash *hash)
Definition list.h:119
static void hash_add_fast(struct hash *hash, struct hash_bucket *bucket, const void *key, uint64_t hv, void *value)
Definition list.h:149
static struct hash_bucket * hash_bucket(struct hash *hash, uint64_t hv)
Definition list.h:125
static uint64_t hash_value(const struct hash *hash, const void *key)
Definition list.h:107
void management_check_bytecount_server(struct multi_context *multi, struct timeval *timeval)
Definition manage.c:4284
void management_connection_established(struct management *man, struct man_def_auth_context *mdac, const struct env_set *es)
Definition manage.c:3107
void management_notify_client_close(const struct management *man, struct man_def_auth_context *mdac, const struct env_set *es)
Definition manage.c:3117
void management_set_callback(struct management *man, const struct management_callback *cb)
Definition manage.c:2864
void management_learn_addr(struct man_def_auth_context *mdac, const struct mroute_addr *addr, const bool primary)
Definition manage.c:3130
#define MCF_SERVER
Definition manage.h:175
void mbuf_add_item(struct mbuf_set *ms, const struct mbuf_item *item)
Definition mbuf.c:89
struct mbuf_buffer * mbuf_alloc_buf(const struct buffer *buf)
Definition mbuf.c:65
void mbuf_free_buf(struct mbuf_buffer *mb)
Definition mbuf.c:76
void mbuf_dereference_instance(struct mbuf_set *ms, struct multi_instance *mi)
Definition mbuf.c:152
bool mbuf_extract_item(struct mbuf_set *ms, struct mbuf_item *item)
Definition mbuf.c:111
void mbuf_free(struct mbuf_set *ms)
Definition mbuf.c:50
struct mbuf_set * mbuf_init(unsigned int size)
Definition mbuf.c:38
#define MF_UNICAST
Definition mbuf.h:47
static int mbuf_maximum_queued(const struct mbuf_set *ms)
Definition mbuf.h:93
void mroute_addr_mask_host_bits(struct mroute_addr *ma)
Definition mroute.c:319
void mroute_helper_add_iroute46(struct mroute_helper *mh, int netbits)
Definition mroute.c:521
const char * mroute_addr_print_ex(const struct mroute_addr *ma, const unsigned int flags, struct gc_arena *gc)
Definition mroute.c:378
bool mroute_extract_openvpn_sockaddr(struct mroute_addr *addr, const struct openvpn_sockaddr *osaddr, bool use_port)
Definition mroute.c:255
const char * mroute_addr_print(const struct mroute_addr *ma, struct gc_arena *gc)
Definition mroute.c:372
void mroute_helper_del_iroute46(struct mroute_helper *mh, int netbits)
Definition mroute.c:536
bool mroute_learnable_address(const struct mroute_addr *addr, struct gc_arena *gc)
Definition mroute.c:64
bool mroute_addr_compare_function(const void *key1, const void *key2)
Definition mroute.c:366
struct mroute_helper * mroute_helper_init(int ageable_ttl_secs)
Definition mroute.c:483
void mroute_addr_init(struct mroute_addr *addr)
Definition mroute.c:39
uint64_t mroute_addr_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
Definition mroute.c:359
void mroute_helper_free(struct mroute_helper *mh)
Definition mroute.c:552
#define MROUTE_EXTRACT_SUCCEEDED
Definition mroute.h:38
#define MROUTE_EXTRACT_MCAST
Definition mroute.h:40
static unsigned int mroute_extract_addr_from_packet(struct mroute_addr *src, struct mroute_addr *dest, uint16_t vid, const struct buffer *buf, int tunnel_type)
Definition mroute.h:183
#define MR_WITH_NETBITS
Definition mroute.h:70
#define MR_WITH_PROTO
Definition mroute.h:76
static void mroute_extract_in_addr_t(struct mroute_addr *dest, const in_addr_t src)
Definition mroute.h:244
#define MR_ADDR_IPV4
Definition mroute.h:62
#define MR_ONLINK_DCO_ADDR
Definition mroute.h:79
static bool mroute_addr_equal(const struct mroute_addr *a1, const struct mroute_addr *a2)
Definition mroute.h:209
#define MAPF_SHOW_FAMILY
Definition mroute.h:158
#define MROUTE_EXTRACT_BCAST
Definition mroute.h:39
#define MR_ADDR_IPV6
Definition mroute.h:63
#define MR_ADDR_MASK
Definition mroute.h:64
void multi_tcp_instance_specific_free(struct multi_instance *mi)
Definition mtcp.c:116
void multi_tcp_delete_event(struct multi_io *multi_io, event_t event)
Definition mtcp.c:122
bool multi_tcp_instance_specific_init(struct multi_context *m, struct multi_instance *mi)
Definition mtcp.c:94
void multi_tcp_dereference_instance(struct multi_io *multi_io, struct multi_instance *mi)
Definition mtcp.c:131
#define BUF_SIZE(f)
Definition mtu.h:188
static const char * np(const char *str)
Definition multi-auth.c:146
static struct multi_instance * multi_learn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr, const unsigned int flags)
Definition multi.c:1013
static void multi_schedule_context_wakeup(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:2943
bool multi_check_push_ifconfig_ipv6_extra_route(const struct options *o, const struct in6_addr *dest)
Determines if the ifconfig_ipv6_local address falls into the range of the local IP addresses of the V...
Definition multi.c:4467
static void multi_unlearn_in_addr_t(struct multi_context *m, struct multi_instance *mi, in_addr_t a)
Definition multi.c:4335
static void multi_client_connect_early_setup(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:2436
static void multi_reap_free(struct multi_reap *mr)
Definition multi.c:215
static bool ccs_gen_deferred_ret_file(struct multi_instance *mi)
Create a temporary file for the return value of client connect and puts it into the client_connect_de...
Definition multi.c:1898
static void multi_process_float(struct multi_context *m, struct multi_instance *mi, struct link_socket *sock)
Handles peer floating.
Definition multi.c:3166
static void multi_reap_range(const struct multi_context *m, uint32_t start_bucket, uint32_t end_bucket)
Definition multi.c:161
struct multi_instance * multi_create_instance(struct multi_context *m, const struct mroute_addr *real, struct link_socket *sock)
Definition multi.c:705
static void multi_add_iroutes(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:1275
void multi_ifconfig_pool_persist(struct multi_context *m, bool force)
Definition multi.c:150
static enum client_connect_return multi_client_connect_compress_migrate(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Do the necessary modification for doing the compress migrate.
Definition multi.c:2471
static void multi_top_free(struct multi_context *m)
Definition multi.c:3839
static void multi_signal_instance(struct multi_context *m, struct multi_instance *mi, const int sig)
Definition multi.c:3236
void multi_reap_process_dowork(const struct multi_context *m)
Definition multi.c:202
static bool override_locked_username(struct multi_instance *mi)
Overrides the locked username with the username of –override-username.
Definition multi.c:2572
static int management_callback_n_clients(void *arg)
Definition multi.c:3925
bool multi_process_signal(struct multi_context *m)
Definition multi.c:3885
static void multi_select_virtual_addr(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:1406
static bool multi_check_dest_addr_allowed(struct multi_context *m, struct multi_instance *mi, struct mroute_addr *real)
This methods checks if a client instance is allowed to use an address.
Definition multi.c:3086
static void multi_get_timeout(struct multi_context *multi, struct timeval *timeval)
Determines the earliest wakeup interval based on periodic operations.
Definition multi.c:4187
void multi_close_instance_on_signal(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:3224
bool multi_process_post(struct multi_context *m, struct multi_instance *mi, const unsigned int flags)
Perform postprocessing of a VPN tunnel instance.
Definition multi.c:2985
static void multi_connection_established(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:2646
void multi_process_per_second_timers_dowork(struct multi_context *m)
Definition multi.c:3803
static void multi_set_virtual_addr_env(struct multi_instance *mi)
Definition multi.c:1547
static void multi_client_connect_setenv(struct multi_instance *mi)
Definition multi.c:1691
struct multi_instance * multi_get_queue(struct mbuf_set *ms)
Definition multi.c:3656
static void setenv_stats(struct context *c)
Definition multi.c:504
bool multi_process_timeout(struct multi_context *m, const unsigned int mpp_flags)
Definition multi.c:3692
static void multi_unlearn_addr(struct multi_context *m, struct multi_instance *mi, const struct mroute_addr *addr)
Definition multi.c:4300
static int management_callback_kill_by_cn(void *arg, const char *del_cn)
Definition multi.c:3932
static void multi_client_disconnect_script(struct multi_instance *mi)
Definition multi.c:524
static bool stale_route_check_trigger(struct multi_context *m)
Definition multi.c:3792
struct multi_instance * lookup_by_cid(struct multi_context *m, const unsigned long cid)
Definition multi.c:3992
static bool management_kill_by_cid(void *arg, const unsigned long cid, const char *kill_msg)
Definition multi.c:4006
static enum client_connect_return multi_client_connect_call_script(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Runs the –client-connect script if one is defined.
Definition multi.c:2209
static void multi_init(struct context *t)
Definition multi.c:269
static void generate_prefix(struct multi_instance *mi)
Definition multi.c:448
static void multi_del_iroutes(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:477
static enum client_connect_return multi_client_connect_call_plugin_v1(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Definition multi.c:2029
enum client_connect_return(* multi_client_connect_handler)(struct multi_context *m, struct multi_instance *mi, bool from_deferred, uint64_t *option_types_found)
Definition multi.c:2553
static void management_delete_event(void *arg, event_t event)
Definition multi.c:3982
static uint64_t cid_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
Definition multi.c:232
static bool multi_client_setup_dco_initial(struct multi_context *m, struct multi_instance *mi, struct gc_arena *gc)
Definition multi.c:2267
enum client_connect_return multi_client_connect_mda(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Definition multi.c:1658
static void multi_uninit(struct multi_context *m)
Definition multi.c:655
const char * multi_instance_string(const struct multi_instance *mi, bool null, struct gc_arena *gc)
Definition multi.c:418
static unsigned int compute_wakeup_sigma(const struct timeval *delta)
Definition multi.c:2919
static bool learn_address_script(const struct multi_context *m, const struct multi_instance *mi, const char *op, const struct mroute_addr *addr)
Definition multi.c:83
static void multi_unicast(struct multi_context *m, const struct buffer *buf, struct multi_instance *mi)
Definition multi.c:2861
static void multi_client_connect_post(struct multi_context *m, struct multi_instance *mi, const char *dc_file, uint64_t *option_types_found)
Definition multi.c:1593
void multi_close_instance(struct multi_context *m, struct multi_instance *mi, bool shutdown)
Definition multi.c:555
static bool management_client_pending_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id, const char *extra, unsigned int timeout)
Definition multi.c:4041
static void multi_push_restart_schedule_exit(struct multi_context *m, bool next_server)
Definition multi.c:3852
static void multi_top_init(struct context *top)
Definition multi.c:3832
static struct tls_session * lookup_session_by_mda_key_id(struct tls_multi *multi, const unsigned int mda_key_id)
Definition multi.c:4023
static bool ccs_gen_config_file(struct multi_instance *mi)
Create a temporary file for the config directives of the client connect script and puts it into the c...
Definition multi.c:2003
static enum client_connect_return multi_client_connect_call_plugin_v2(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Definition multi.c:2119
static void check_stale_routes(struct multi_context *m)
Definition multi.c:1356
bool multi_check_push_ifconfig_extra_route(const struct options *o, in_addr_t dest)
Determines if the ifconfig_push_local address falls into the range of the local IP addresses of the V...
Definition multi.c:4447
static void multi_process_incoming_link_data(struct multi_context *m, bool floated, struct link_socket *sock)
Process incoming data packet from clients.
Definition multi.c:3355
static bool management_client_auth(void *arg, const unsigned long cid, const unsigned int mda_key_id, const bool auth, const char *reason, const char *client_reason, struct buffer_list *cc_config)
Definition multi.c:4068
static void multi_client_connect_late_setup(struct multi_context *m, struct multi_instance *mi, const uint64_t option_types_found)
Definition multi.c:2313
static void multi_bcast(struct multi_context *m, const struct buffer *buf, const struct multi_instance *sender_instance, uint16_t vid)
Definition multi.c:2878
static int management_callback_kill_by_addr(void *arg, const in_addr_t addr, const uint16_t port, const uint8_t proto)
Definition multi.c:3954
static void multi_reap_all(const struct multi_context *m)
Definition multi.c:185
static void multi_print_status(struct multi_context *m, struct status_output *so, const int version)
Definition multi.c:789
void route_quota_exceeded(const struct multi_instance *mi)
Definition multi.c:3746
void ungenerate_prefix(struct multi_instance *mi)
Definition multi.c:465
void multi_assign_peer_id(struct multi_context *m, struct multi_instance *mi)
Assigns a peer-id to a a client and adds the instance to the the instances array of the multi_context...
Definition multi.c:4150
static struct multi_reap * multi_reap_new(uint32_t buckets_per_pass)
Definition multi.c:191
static void multi_delete_dup(struct multi_context *m, struct multi_instance *new_mi)
Definition multi.c:1322
static struct multi_instance * multi_get_instance_by_virtual_addr(struct multi_context *m, const struct mroute_addr *addr, bool cidr_routing)
Definition multi.c:1102
void init_management_callback_multi(struct multi_context *m)
Definition multi.c:4123
static void multi_unlearn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6)
Definition multi.c:4353
static void multi_add_mbuf(struct multi_context *m, struct multi_instance *mi, struct mbuf_buffer *mb)
Definition multi.c:2842
static enum client_connect_return ccs_test_deferred_ret_file(struct multi_instance *mi)
Tests whether the deferred return value file exists and returns the contained return value.
Definition multi.c:1930
static void multi_client_connect_post_plugin(struct multi_context *m, struct multi_instance *mi, const struct plugin_return *pr, uint64_t *option_types_found)
Definition multi.c:1619
static uint32_t reap_buckets_per_pass(uint32_t n_buckets)
Definition multi.c:224
static char * management_get_peer_info(void *arg, const unsigned long cid)
Definition multi.c:4105
static bool multi_client_set_protocol_options(struct context *c)
Calculates the options that depend on the client capabilities based on local options and available pe...
Definition multi.c:1721
void unlearn_ifconfig_ipv6(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:4379
static struct multi_instance * multi_learn_in_addr_t(struct multi_context *m, struct multi_instance *mi, in_addr_t a, int netbits, bool primary)
Definition multi.c:1177
static bool is_exit_restart(int sig)
Definition multi.c:3846
static bool ifconfig_push_constraint_satisfied(const struct context *c)
Definition multi.c:1386
static void set_cc_config(struct multi_instance *mi, struct buffer_list *cc_config)
Definition multi.c:75
void multi_process_drop_outgoing_tun(struct multi_context *m, const unsigned int mpp_flags)
Definition multi.c:3724
static bool cid_compare_function(const void *key1, const void *key2)
Definition multi.c:239
static void multi_client_disconnect_setenv(struct multi_instance *mi)
Definition multi.c:511
void unlearn_ifconfig(struct multi_context *m, struct multi_instance *mi)
Definition multi.c:4367
void update_vhash(struct multi_context *m, struct multi_instance *mi, const char *new_ip, const char *new_ipv6)
Update the vhash with new IP/IPv6 addresses in the multi_context when a push-update message containin...
Definition multi.c:4401
static bool multi_client_generate_tls_keys(struct context *c)
Generates the data channel keys.
Definition multi.c:2290
static enum client_connect_return multi_client_connect_source_ccd(struct multi_context *m, struct multi_instance *mi, bool deferred, uint64_t *option_types_found)
Try to source a dynamic config file from the –client-config-dir directory.
Definition multi.c:2503
static struct multi_instance * multi_learn_in6_addr(struct multi_context *m, struct multi_instance *mi, struct in6_addr a6, int netbits, bool primary)
Definition multi.c:1223
static void management_callback_status(void *arg, const int version, struct status_output *so)
Definition multi.c:3910
static void ccs_delete_config_file(struct multi_instance *mi)
Deletes the temporary file for the config directives of the client connect script and removes it into...
Definition multi.c:1980
static void ccs_delete_deferred_ret_file(struct multi_instance *mi)
Delete the temporary file for the return value of client connect It also removes it from client_conne...
Definition multi.c:1873
static const multi_client_connect_handler client_connect_handlers[]
Definition multi.c:2557
static enum client_connect_return multi_client_connect_script_deferred(struct multi_context *m, struct multi_instance *mi, uint64_t *option_types_found)
Definition multi.c:2168
Header file for server-mode related structures and functions.
client_connect_return
Return values used by the client connect call-back functions.
Definition multi.h:221
@ CC_RET_DEFERRED
Definition multi.h:224
@ CC_RET_FAILED
Definition multi.h:222
@ CC_RET_SKIPPED
Definition multi.h:225
@ CC_RET_SUCCEEDED
Definition multi.h:223
static bool multi_output_queue_ready(const struct multi_context *m, const struct multi_instance *mi)
Definition multi.h:386
#define MULTI_PREFIX_MAX_LENGTH
Definition multi.h:44
#define MULTI_CHECK_SIG(m)
Definition multi.h:696
#define REAP_MIN
Definition multi.h:549
static void set_prefix(struct multi_instance *mi)
Definition multi.h:518
static void multi_route_del(struct multi_route *route)
Definition multi.h:477
static void multi_reap_process(const struct multi_context *m)
Definition multi.h:563
static void route_quota_inc(struct multi_instance *mi)
Definition multi.h:430
void multi_process_incoming_dco(dco_context_t *dco)
Process an incoming DCO message (from kernel space).
#define MULTI_ROUTE_CACHE
Definition multi.h:236
static void clear_prefix(void)
Definition multi.h:530
static bool multi_route_defined(const struct multi_context *m, const struct multi_route *r)
Definition multi.h:486
#define REAP_DIVISOR
Definition multi.h:548
#define MULTI_CACHE_ROUTE_TTL
Definition multi.h:556
#define MPP_CLOSE_ON_SIGNAL
Definition multi.h:271
#define REAP_MAX
Definition multi.h:550
static void multi_instance_dec_refcount(struct multi_instance *mi)
Definition multi.h:467
static void multi_instance_inc_refcount(struct multi_instance *mi)
Definition multi.h:461
static void multi_get_timeout_instance(struct multi_context *m, struct timeval *dest)
Definition multi.h:591
#define CLIENT_CONNECT_OPT_MASK
Definition multi.h:651
static void multi_set_pending(struct multi_context *m, struct multi_instance *mi)
Definition multi.h:699
#define MULTI_ROUTE_AGEABLE
Definition multi.h:237
#define MPP_RECORD_TOUCH
Definition multi.h:272
#define MULTI_ROUTE_PERMANENT
Definition multi.h:238
#define MPP_PRE_SELECT
Definition multi.h:270
static void multi_process_per_second_timers(struct multi_context *m)
Definition multi.h:572
static bool route_quota_test(const struct multi_instance *mi)
Definition multi.h:443
struct multi_io * multi_io_init(const int maxclients)
Definition multi_io.c:108
void multi_io_process_io(struct multi_context *m)
Definition multi_io.c:455
void multi_io_free(struct multi_io *multi_io)
Definition multi_io.c:147
int multi_io_wait(struct multi_context *m)
Definition multi_io.c:192
void multi_io_action(struct multi_context *m, struct multi_instance *mi, int action, bool poll)
Definition multi_io.c:580
#define TA_TIMEOUT
Definition multi_io.h:45
#define CLEAR(x)
Definition basic.h:32
#define M_OPTERR
Definition error.h:101
static bool check_debug_level(msglvl_t level)
Definition error.h:253
#define M_USAGE
Definition error.h:107
#define M_NONFATAL
Definition error.h:91
#define dmsg(flags,...)
Definition error.h:164
#define msg(flags,...)
Definition error.h:152
unsigned int msglvl_t
Definition error.h:77
#define ASSERT(x)
Definition error.h:221
#define M_WARN
Definition error.h:92
#define M_ERRNO
Definition error.h:95
static bool is_cas_pending(enum multi_status cas)
Definition openvpn.h:210
#define MAX_PEER_ID
Definition openvpn.h:552
#define CM_TOP
Definition openvpn.h:480
const char title_string[]
Definition options.c:73
bool has_udp_in_local_list(const struct options *options)
Definition options.c:7930
#define MODE_SERVER
Definition options.h:265
static bool dco_enabled(const struct options *o)
Returns whether the current configuration has dco enabled.
Definition options.h:971
void options_string_import(struct options *options, const char *config, const msglvl_t msglevel, const uint64_t permission_mask, uint64_t *option_types_found, struct env_set *es)
#define OPT_P_COMP
Definition options.h:741
void options_server_import(struct options *o, const char *filename, msglvl_t msglevel, uint64_t permission_mask, uint64_t *option_types_found, struct env_set *es)
const char * time_string(time_t t, tv_usec_t usec, bool show_usec, struct gc_arena *gc)
Definition otime.c:104
struct frequency_limit * frequency_limit_init(int max, int per)
Definition otime.c:137
time_t now
Definition otime.c:33
void frequency_limit_free(struct frequency_limit *f)
Definition otime.c:152
static int openvpn_gettimeofday(struct timeval *tv, void *tz)
Definition otime.h:71
static void tv_add(struct timeval *dest, const struct timeval *src)
Definition otime.h:129
@ OVPN_DEL_PEER_REASON_EXPIRED
@ OVPN_DEL_PEER_REASON_TRANSPORT_DISCONNECT
@ OVPN_DEL_PEER_REASON_TRANSPORT_ERROR
@ OVPN_DEL_PEER_REASON_USERSPACE
@ OVPN_CMD_FLOAT_PEER
@ OVPN_CMD_SWAP_KEYS
@ OVPN_CMD_DEL_PEER
bool platform_test_file(const char *filename)
Return true if filename can be opened for read.
Definition platform.c:683
const char * platform_create_temp_file(const char *directory, const char *prefix, struct gc_arena *gc)
Create a temporary file in directory, returns the filename of the created file.
Definition platform.c:540
const char * platform_gen_path(const char *directory, const char *filename, struct gc_arena *gc)
Put a directory and filename together.
Definition platform.c:619
bool platform_unlink(const char *filename)
Definition platform.c:487
void plugin_return_free(struct plugin_return *pr)
Definition plugin.c:986
void plugin_return_get_column(const struct plugin_return *src, struct plugin_return *dest, const char *colname)
Definition plugin.c:972
bool plugin_defined(const struct plugin_list *pl, const int type)
Definition plugin.c:904
static void plugin_return_init(struct plugin_return *pr)
Definition plugin.h:163
static int plugin_call(const struct plugin_list *pl, const int type, const struct argv *av, struct plugin_return *pr, struct env_set *es)
Definition plugin.h:195
static bool plugin_return_defined(const struct plugin_return *pr)
Definition plugin.h:157
ifconfig_pool_handle ifconfig_pool_acquire(struct ifconfig_pool *pool, in_addr_t *local, in_addr_t *remote, struct in6_addr *remote_ipv6, const char *common_name)
Definition pool.c:297
bool ifconfig_pool_release(struct ifconfig_pool *pool, ifconfig_pool_handle hand, const bool hard)
Definition pool.c:349
void ifconfig_pool_write(struct ifconfig_pool_persist *persist, const struct ifconfig_pool *pool)
Definition pool.c:712
bool ifconfig_pool_write_trigger(struct ifconfig_pool_persist *persist)
Definition pool.c:573
void ifconfig_pool_free(struct ifconfig_pool *pool)
Definition pool.c:281
void ifconfig_pool_read(struct ifconfig_pool_persist *persist, struct ifconfig_pool *pool)
Definition pool.c:586
struct ifconfig_pool * ifconfig_pool_init(const bool ipv4_pool, enum pool_type type, in_addr_t start, in_addr_t end, const bool duplicate_cn, const bool ipv6_pool, const struct in6_addr ipv6_base, const int ipv6_netbits)
Definition pool.c:140
pool_type
Definition pool.h:35
@ IFCONFIG_POOL_30NET
Definition pool.h:36
@ IFCONFIG_POOL_INDIV
Definition pool.h:37
#define DEV_TYPE_TAP
Definition proto.h:36
#define DEV_TYPE_UNDEF
Definition proto.h:34
#define TOP_NET30
Definition proto.h:41
#define DEV_TYPE_TUN
Definition proto.h:35
#define TOP_P2P
Definition proto.h:42
#define TOP_SUBNET
Definition proto.h:43
int process_incoming_push_request(struct context *c)
Definition push.c:986
void push_option(struct options *o, const char *opt, msglvl_t msglevel)
Definition push.c:896
void send_restart(struct context *c, const char *kill_msg)
Definition push.c:494
bool send_auth_pending_messages(struct tls_multi *tls_multi, struct tls_session *session, const char *extra, unsigned int timeout)
Sends the auth pending control messages to a client.
Definition push.c:433
void remove_iroutes_from_push_route_list(struct options *o)
Definition push.c:1147
bool management_callback_send_push_update_by_cid(void *arg, unsigned long cid, const char *options)
Definition push_util.c:365
bool management_callback_send_push_update_broadcast(void *arg, const char *options)
Definition push_util.c:357
void initial_rate_limit_free(struct initial_packet_rate_limit *irl)
free the initial-packet rate limiter structure
struct initial_packet_rate_limit * initial_rate_limit_init(int max_per_period, int period_length)
allocate and initialize the initial-packet rate limiter structure
bool ipv6_net_contains_host(const struct in6_addr *network, unsigned int bits, const struct in6_addr *host)
check whether an IPv6 host address is covered by a given network/bits
Definition route.c:705
static int openvpn_run_script(const struct argv *a, const struct env_set *es, const unsigned int flags, const char *hook)
Will run a script and return the exit code of the script if between 0 and 255, -1 otherwise.
Definition run_command.h:89
void schedule_remove_entry(struct schedule *s, struct schedule_entry *e)
Definition schedule.c:388
struct schedule * schedule_init(void)
Definition schedule.c:373
void schedule_free(struct schedule *s)
Definition schedule.c:382
static void schedule_add_entry(struct schedule *s, struct schedule_entry *e, const struct timeval *tv, unsigned int sigma)
Add a struct schedule_entry to the scheduler btree or update an existing entry with a new wakeup time...
Definition schedule.h:98
int signal_reset(struct signal_info *si, int signum)
Clear the signal if its current value equals signum.
Definition sig.c:262
void remap_signal(struct context *c)
Definition sig.c:588
void throw_signal(const int signum)
Throw a hard signal.
Definition sig.c:175
void print_signal(const struct signal_info *si, const char *title, msglvl_t msglevel)
Definition sig.c:290
void register_signal(struct signal_info *si, int signum, const char *signal_text)
Register a soft signal in the signal_info struct si respecting priority.
Definition sig.c:228
#define IS_SIG(c)
Definition sig.h:47
void setenv_trusted(struct env_set *es, const struct link_socket_info *info)
Definition socket.c:1854
void setenv_in_addr_t(struct env_set *es, const char *name_prefix, in_addr_t addr, const unsigned int flags)
void setenv_in6_addr(struct env_set *es, const char *name_prefix, const struct in6_addr *addr, const unsigned int flags)
const char * print_in6_addr(struct in6_addr a6, unsigned int flags, struct gc_arena *gc)
const char * print_in_addr_t(in_addr_t addr, unsigned int flags, struct gc_arena *gc)
#define IA_EMPTY_IF_UNDEF
Definition socket_util.h:89
static bool proto_is_dgram(int proto)
Return if the protocol is datagram (UDP).
#define SA_SET_IF_NONZERO
void tls_update_remote_addr(struct tls_multi *multi, const struct link_socket_actual *addr)
Updates remote address in TLS sessions.
Definition ssl.c:4274
void tls_session_soft_reset(struct tls_multi *tls_multi)
Definition ssl.c:1833
bool tls_session_update_crypto_params(struct tls_multi *multi, struct tls_session *session, struct options *options, struct frame *frame, struct frame *frame_fragment, struct link_socket_info *lsi, dco_context_t *dco)
Update TLS session crypto parameters (cipher and auth) and derive data channel keys based on the supp...
Definition ssl.c:1705
#define IV_PROTO_CC_EXIT_NOTIFY
Support for explicit exit notify via control channel This also includes support for the protocol-flag...
Definition ssl.h:102
#define IV_PROTO_DATA_EPOCH
Support the extended packet id and epoch format for data channel packets.
Definition ssl.h:111
#define IV_PROTO_DATA_V2
Support P_DATA_V2.
Definition ssl.h:80
#define IV_PROTO_TLS_KEY_EXPORT
Supports key derivation via TLS key material exporter [RFC5705].
Definition ssl.h:87
#define IV_PROTO_DYN_TLS_CRYPT
Support to dynamic tls-crypt (renegotiation with TLS-EKM derived tls-crypt key).
Definition ssl.h:108
#define IV_PROTO_REQUEST_PUSH
Assume client will send a push request and server does not need to wait for a push-request to send a ...
Definition ssl.h:84
#define IV_PROTO_NCP_P2P
Support doing NCP in P2P mode.
Definition ssl.h:95
@ CAS_CONNECT_DONE
Definition ssl_common.h:593
@ CAS_PENDING_DEFERRED
Waiting on an async option import handler.
Definition ssl_common.h:583
@ CAS_WAITING_AUTH
Initial TLS connection established but deferred auth is not yet finished.
Definition ssl_common.h:581
@ CAS_PENDING_DEFERRED_PARTIAL
at least handler succeeded but another is still pending
Definition ssl_common.h:584
@ CAS_PENDING
Options import (Connect script/plugin, ccd,...).
Definition ssl_common.h:582
@ CAS_NOT_CONNECTED
Definition ssl_common.h:580
@ CAS_FAILED
Option import failed or explicitly denied the client.
Definition ssl_common.h:585
@ KS_AUTH_FALSE
Key state is not authenticated.
Definition ssl_common.h:154
@ KS_AUTH_DEFERRED
Key state authentication is being deferred, by async auth.
Definition ssl_common.h:155
static const struct key_state * get_primary_key(const struct tls_multi *multi)
gets an item of key_state objects in the order they should be scanned by data channel modules.
Definition ssl_common.h:757
#define SSLF_USERNAME_AS_COMMON_NAME
Definition ssl_common.h:425
char * ncp_get_best_cipher(const char *server_list, const char *peer_info, const char *remote_cipher, struct gc_arena *gc)
Iterates through the ciphers in server_list and return the first cipher that is also supported by the...
Definition ssl_ncp.c:238
const char * tls_peer_ncp_list(const char *peer_info, struct gc_arena *gc)
Returns the support cipher list from the peer according to the IV_NCP and IV_CIPHER values in peer_in...
Definition ssl_ncp.c:217
const char * ncp_expanded_ciphers(struct options *o, struct gc_arena *gc)
returns the o->ncp_ciphers in brackets, e.g.
Definition ssl_ncp.c:628
Control Channel SSL/Data dynamic negotiation Module This file is split from ssl.h to be able to unit ...
SSL utility functions.
static unsigned int extract_iv_proto(const char *peer_info)
Extracts the IV_PROTO variable and returns its value or 0 if it cannot be extracted.
Definition ssl_util.h:77
bool ssl_verify_username_length(struct tls_session *session, const char *username)
Checks if the username length is valid to use.
bool tls_authenticate_key(struct tls_multi *multi, const unsigned int mda_key_id, const bool auth, const char *client_reason)
bool cert_hash_compare(const struct cert_hash_set *chs1, const struct cert_hash_set *chs2)
Compares certificates hashes, returns true if hashes are equal.
Definition ssl_verify.c:229
void tls_lock_cert_hash_set(struct tls_multi *multi)
Locks the certificate hash set used in the given tunnel.
Definition ssl_verify.c:286
void tls_lock_common_name(struct tls_multi *multi)
Locks the common name field for the given tunnel.
Definition ssl_verify.c:132
const char * tls_username(const struct tls_multi *multi, const bool null)
Returns the username field for the given tunnel.
Definition ssl_verify.c:172
void set_common_name(struct tls_session *session, const char *common_name)
Sets the common name field for the given tunnel.
Definition ssl_verify.c:85
void auth_set_client_reason(struct tls_multi *multi, const char *client_reason)
Sets the reason why authentication of a client failed.
Definition ssl_verify.c:814
const char * tls_common_name(const struct tls_multi *multi, const bool null)
Returns the common name field for the given tunnel.
Definition ssl_verify.c:107
Control Channel Verification Module.
bool status_trigger(struct status_output *so)
Definition status.c:123
void status_printf(struct status_output *so, const char *format,...)
Definition status.c:212
struct status_output * status_open(const char *filename, const int refresh_freq, const int msglevel, const struct virtual_output *vout, const unsigned int flags)
Definition status.c:59
void status_flush(struct status_output *so)
Definition status.c:147
void status_reset(struct status_output *so)
Definition status.c:138
bool status_close(struct status_output *so)
Definition status.c:178
Definition argv.h:35
One node in a buffer_list linked list.
Definition buffer.h:2163
struct buffer_entry * next
Pointer to the next node, or NULL.
Definition buffer.h:2165
struct buffer buf
The buffer stored in this list node.
Definition buffer.h:2164
A singly-linked list of buffers, with head/tail pointers for O(1) push.
Definition buffer.h:2170
struct buffer_entry * head
Next item to pop/peek.
Definition buffer.h:2171
Wrapper structure for dynamically allocated memory.
Definition buffer.h:71
uint8_t * data
Pointer to the allocated memory.
Definition buffer.h:78
int len
Length in bytes of the actual content within the allocated memory.
Definition buffer.h:76
Detached client connection state.
Definition multi.h:71
uint64_t option_types_found
Definition multi.h:76
char * config_file
The temporary file name that contains the config directives returned by the client-connect script.
Definition multi.h:88
char * deferred_ret_file
The temporary file name that contains the return status of the client-connect script if it exits with...
Definition multi.h:82
unsigned int flags
Definition comp.h:77
int explicit_exit_notification
Definition options.h:152
int fragment
Definition options.h:143
struct ifconfig_pool_persist * ifconfig_pool_persist
Definition openvpn.h:198
struct status_output * status_output
Definition openvpn.h:186
struct tuntap * tuntap
Tun/tap virtual network interface.
Definition openvpn.h:173
bool push_request_received
Definition openvpn.h:424
counter_type link_read_bytes
Definition openvpn.h:267
counter_type link_write_bytes
Definition openvpn.h:270
bool push_ifconfig_ipv6_defined
Definition openvpn.h:431
struct fragment_master * fragment
Definition openvpn.h:253
bool push_ifconfig_defined
Definition openvpn.h:425
counter_type dco_read_bytes
Definition openvpn.h:268
struct man_def_auth_context mda_context
Definition openvpn.h:450
counter_type dco_write_bytes
Definition openvpn.h:271
struct env_set * es
Definition openvpn.h:420
struct tls_multi * tls_multi
TLS state structure for this VPN tunnel.
Definition openvpn.h:324
struct frame frame
Definition openvpn.h:249
struct in6_addr push_ifconfig_ipv6_remote
Definition openvpn.h:434
struct link_socket_actual from
Definition openvpn.h:246
struct frame frame_fragment
Definition openvpn.h:254
int push_ifconfig_ipv6_netbits
Definition openvpn.h:433
struct buffer to_link
Definition openvpn.h:377
struct buffer to_tun
Definition openvpn.h:376
struct in6_addr push_ifconfig_ipv6_local
Definition openvpn.h:432
struct link_socket ** link_sockets
Definition openvpn.h:238
in_addr_t push_ifconfig_local_alias
Definition openvpn.h:429
struct link_socket_info ** link_socket_infos
Definition openvpn.h:239
struct link_socket_actual * to_link_addr
Definition openvpn.h:245
in_addr_t push_ifconfig_remote_netmask
Definition openvpn.h:428
struct buffer buf
Definition openvpn.h:375
struct timeval timeval
Time to next event of timers and similar.
Definition openvpn.h:396
struct event_set * event_set
Definition openvpn.h:231
struct context_buffers * buffers
Definition openvpn.h:367
in_addr_t push_ifconfig_local
Definition openvpn.h:427
Contains all state information for one tunnel.
Definition openvpn.h:471
int mode
Role of this context within the OpenVPN process.
Definition openvpn.h:484
struct multi_context * multi
Pointer to the main P2MP context.
Definition openvpn.h:489
bool did_dco_iroutes
Whether DCO iroutes have been installed.
Definition openvpn.h:510
struct signal_info * sig
Internal error signaling object.
Definition openvpn.h:500
openvpn_net_ctx_t net_ctx
Networking API opaque context.
Definition openvpn.h:498
struct plugin_list * plugins
List of plug-ins.
Definition openvpn.h:502
struct context_2 c2
Level 2 context.
Definition openvpn.h:516
struct env_set * es
Set of environment variables.
Definition openvpn.h:496
struct options options
Options loaded from command line or configuration file.
Definition openvpn.h:472
struct context_1 c1
Level 1 context.
Definition openvpn.h:515
Security parameter state for processing data channel packets.
Definition crypto.h:293
struct key_ctx_bi key_ctx_bi
OpenSSL cipher and HMAC contexts for both sending and receiving directions.
Definition crypto.h:294
int signal_received
Definition multi.h:62
struct timeval wakeup
Definition multi.h:63
union event_arg::@352313260244035237115140212234220346176163201310 u
struct multi_instance * mi
Definition event.h:144
event_arg_t type
Definition event.h:141
struct buffer outgoing
Buffer containing the remaining parts of the fragmented packet being sent.
Definition fragment.h:172
Packet geometry parameters.
Definition mtu.h:113
struct frame::@074234134026241341315172337061247271261307273127 buf
int payload_size
the maximum size that a payload that our buffers can hold from either tun device or network link.
Definition mtu.h:118
int headroom
the headroom in the buffer, this is choosen to allow all potential header to be added before the pack...
Definition mtu.h:124
Garbage collection arena used to keep track of dynamically allocated memory.
Definition buffer.h:127
void * value
Definition list.h:41
const void * key
Definition list.h:42
Definition list.h:56
struct iroute_ipv6 * next
Definition route.h:271
unsigned int netbits
Definition route.h:270
struct in6_addr network
Definition route.h:269
in_addr_t network
Definition route.h:262
int netbits
Definition route.h:263
struct iroute * next
Definition route.h:264
Container for bidirectional cipher and HMAC key material.
Definition crypto.h:240
bool initialized
Definition crypto.h:285
Security parameter state of one TLS and data channel key session.
Definition ssl_common.h:208
struct auth_deferred_status plugin_auth
Definition ssl_common.h:268
unsigned int mda_key_id
Definition ssl_common.h:263
struct auth_deferred_status script_auth
Definition ssl_common.h:269
enum ks_auth_state authenticated
Definition ssl_common.h:259
Container for unidirectional cipher and HMAC key material.
Definition crypto.h:152
unsigned long cid
Definition manage.h:64
char *(* get_peer_info)(void *arg, const unsigned long cid)
Definition manage.h:191
bool(* client_auth)(void *arg, const unsigned long cid, const unsigned int mda_key_id, const bool auth, const char *reason, const char *client_reason, struct buffer_list *cc_config)
Definition manage.h:186
int(* kill_by_addr)(void *arg, const in_addr_t addr, const uint16_t port, const uint8_t proto)
Definition manage.h:181
void(* delete_event)(void *arg, event_t event)
Definition manage.h:182
bool(* push_update_broadcast)(void *arg, const char *options)
Definition manage.h:199
bool(* push_update_by_cid)(void *arg, unsigned long cid, const char *options)
Definition manage.h:200
bool(* client_pending_auth)(void *arg, const unsigned long cid, const unsigned int kid, const char *extra, unsigned int timeout)
Definition manage.h:189
int(* n_clients)(void *arg)
Definition manage.h:183
void(* status)(void *arg, const int version, struct status_output *so)
Definition manage.h:178
void(* show_net)(void *arg, const msglvl_t msglevel)
Definition manage.h:179
unsigned int flags
Definition manage.h:176
int(* kill_by_cn)(void *arg, const char *common_name)
Definition manage.h:180
bool(* kill_by_cid)(void *arg, const unsigned long cid, const char *kill_msg)
Definition manage.h:185
unsigned int flags
Definition mbuf.h:48
struct buffer buf
Definition mbuf.h:44
struct mbuf_buffer * buffer
Definition mbuf.h:53
struct multi_instance * instance
Definition mbuf.h:54
uint16_t vid
Definition mroute.h:94
uint8_t addr[OPENVPN_ETH_ALEN]
Definition mroute.h:93
uint8_t proto
Definition mroute.h:84
uint8_t type
Definition mroute.h:85
struct mroute_addr::@201361377123046052363312040316220023015150251140::@324142022017217332104337017226063207330251301017 v6
in_port_t port
Definition mroute.h:99
uint8_t len
Definition mroute.h:83
struct mroute_addr::@201361377123046052363312040316220023015150251140::@363302133323255313212060077174173034011260361234 v4
uint8_t netbits
Definition mroute.h:86
unsigned int cache_generation
Definition mroute.h:133
uint8_t net_len[MR_HELPER_NET_LEN]
Definition mroute.h:136
int n_net_len
Definition mroute.h:135
Main OpenVPN server state structure.
Definition multi.h:162
int n_clients
Definition multi.h:188
struct mroute_addr local
Definition multi.h:183
struct schedule * schedule
Definition multi.h:173
struct mbuf_set * mbuf
Set of buffers for passing data channel packets between VPN tunnel instances.
Definition multi.h:174
struct initial_packet_rate_limit * initial_rate_limiter
Definition multi.h:180
struct deferred_signal_schedule_entry deferred_shutdown_signal
Definition multi.h:214
uint32_t max_peerid
highest currently allocated peer-id and maximum allocated/valid index in instances
Definition multi.h:166
struct multi_reap * reaper
Definition multi.h:182
struct multi_io * multi_io
I/O state and events tracker.
Definition multi.h:177
struct hash * hash
VPN tunnel instances indexed by real address of the remote peer.
Definition multi.h:169
struct hash * cid_hash
Definition multi.h:191
unsigned long cid_counter
Definition multi.h:192
struct event_timeout stale_routes_check_et
Definition multi.h:207
int tcp_queue_limit
Definition multi.h:186
struct ifconfig_pool * ifconfig_pool
Definition multi.h:178
struct frequency_limit * new_connection_limiter
Definition multi.h:179
uint32_t max_clients
Definition multi.h:185
struct context top
Storage structure for process-wide configuration.
Definition multi.h:201
int status_file_version
Definition multi.h:187
struct multi_instance * pending
Definition multi.h:195
struct hash * vhash
VPN tunnel instances indexed by virtual address of remote hosts.
Definition multi.h:171
struct multi_instance ** instances
Array of multi_instances with the size of max_clients.
Definition multi.h:163
struct multi_instance ** mpp_touched
Definition multi.h:197
bool enable_c2c
Definition multi.h:184
struct multi_instance * earliest_wakeup
Definition multi.h:196
struct mroute_helper * route_helper
Definition multi.h:181
Server-mode state structure for one single VPN tunnel.
Definition multi.h:102
struct buffer_list * cc_config
Definition multi.h:137
struct client_connect_defer_state client_connect_defer_state
Definition multi.h:144
bool did_cid_hash
Definition multi.h:136
time_t created
Time at which a VPN tunnel instance was created.
Definition multi.h:116
in_addr_t reporting_addr
Definition multi.h:131
char msg_prefix[MULTI_PREFIX_MAX_LENGTH]
Definition multi.h:124
struct mroute_addr real
External network address of the remote peer.
Definition multi.h:121
bool did_iroutes
Definition multi.h:139
ifconfig_pool_handle vaddr_handle
Definition multi.h:123
bool did_real_hash
Definition multi.h:134
struct gc_arena gc
Definition multi.h:112
struct in6_addr reporting_addr_ipv6
Definition multi.h:132
struct timeval wakeup
Definition multi.h:120
struct event_arg ev_arg
this struct will store a pointer to either mi or link_socket, depending on the event type,...
Definition multi.h:107
struct context context
The context structure storing state for this VPN tunnel.
Definition multi.h:142
int n_clients_delta
Definition multi.h:140
time_t last_call
Definition multi.h:55
uint32_t buckets_per_pass
Definition multi.h:54
uint32_t bucket_base
Definition multi.h:53
struct mroute_addr addr
Definition multi.h:233
time_t last_reference
Definition multi.h:242
unsigned int cache_generation
Definition multi.h:241
unsigned int flags
Definition multi.h:239
struct multi_instance * instance
Definition multi.h:234
union openvpn_sockaddr::@051240265251124304325377241125360350250341115171 addr
struct sockaddr_in in4
Definition socket_util.h:43
struct compress_options comp
Definition options.h:410
int push_ifconfig_ipv6_netbits
Definition options.h:523
int max_routes_per_client
Definition options.h:536
const char * ncp_ciphers_conf
The original ncp_ciphers specified by the user in the configuration.
Definition options.h:579
int status_file_version
Definition options.h:407
in_addr_t push_ifconfig_constraint_network
Definition options.h:518
const char * tmp_dir
Definition options.h:466
unsigned int imported_protocol_flags
Definition options.h:723
int stale_routes_ageing_time
Definition options.h:538
bool duplicate_cn
Definition options.h:527
uint32_t real_hash_size
Definition options.h:499
bool use_peer_id
Whether the data channel uses the DATA_V2 header (peer-id).
Definition options.h:703
in_addr_t ifconfig_pool_netmask
Definition options.h:491
const char * ifconfig_ipv6_local
Definition options.h:329
int cf_max
Definition options.h:529
const char * dev_type
Definition options.h:323
bool push_ifconfig_defined
Definition options.h:513
bool ifconfig_pool_defined
Definition options.h:488
bool vlan_tagging
Definition options.h:712
in_addr_t ifconfig_pool_end
Definition options.h:490
bool ifconfig_ipv6_pool_defined
Definition options.h:495
uint32_t max_clients
Definition options.h:535
const char * client_disconnect_script
Definition options.h:502
int n_bcast_buf
Definition options.h:509
const char * ifconfig_local
Definition options.h:327
struct connection_entry ce
Definition options.h:294
struct iroute_ipv6 * iroutes_ipv6
Definition options.h:512
in_addr_t push_ifconfig_local_alias
Definition options.h:516
int topology
Definition options.h:326
const char * ncp_ciphers
Definition options.h:580
uint32_t virtual_hash_size
Definition options.h:500
const char * learn_address_script
Definition options.h:503
const char * ciphername
Definition options.h:575
int cf_initial_max
Definition options.h:532
int stale_routes_check_interval
Definition options.h:537
uint16_t vlan_pvid
Definition options.h:714
int mode
Definition options.h:266
int ifconfig_ipv6_pool_netbits
Definition options.h:497
in_addr_t push_ifconfig_constraint_netmask
Definition options.h:519
bool enable_ncp_fallback
If defined fall back to ciphername if NCP fails.
Definition options.h:576
in_addr_t push_ifconfig_local
Definition options.h:514
struct gc_arena gc
Definition options.h:258
bool push_ifconfig_constraint_defined
Definition options.h:517
int cf_initial_per
Definition options.h:533
bool force_key_material_export
Definition options.h:710
struct iroute * iroutes
Definition options.h:511
struct in6_addr push_ifconfig_ipv6_remote
Definition options.h:524
const char * client_connect_script
Definition options.h:501
bool push_ifconfig_ipv6_defined
Definition options.h:521
int tcp_queue_limit
Definition options.h:510
const char * override_username
Definition options.h:508
struct in6_addr push_ifconfig_ipv6_local
Definition options.h:522
const char * ifconfig_remote_netmask
Definition options.h:328
bool enable_c2c
Definition options.h:526
int cf_per
Definition options.h:530
in_addr_t ifconfig_pool_start
Definition options.h:489
in_addr_t push_ifconfig_remote_netmask
Definition options.h:515
const char * dev
Definition options.h:322
struct in6_addr ifconfig_ipv6_pool_base
Definition options.h:496
const char * client_config_dir
Definition options.h:505
int ifconfig_ipv6_netbits
Definition options.h:330
struct openvpn_plugin_string_list * list[MAX_PLUGINS]
Definition plugin.h:106
Definition schedule.h:41
const char * signal_text
Definition sig.h:44
volatile int signal_received
Definition sig.h:42
Security parameter state for a single VPN tunnel.
Definition ssl_common.h:611
char * auth_token_initial
The first auth-token we sent to a client.
Definition ssl_common.h:683
bool remote_usescomp
remote announced comp-lzo in OCC string
Definition ssl_common.h:705
char * peer_info
A multi-line string of general-purpose info received from peer over control channel.
Definition ssl_common.h:672
char * remote_ciphername
cipher specified in peer's config file
Definition ssl_common.h:704
char * locked_username
The locked username is the username we assume the client is using.
Definition ssl_common.h:649
enum multi_status multi_state
Definition ssl_common.h:632
struct tls_session session[TM_SIZE]
Array of tls_session objects representing control channel sessions with the remote peer.
Definition ssl_common.h:713
struct cert_hash_set * locked_cert_hash_set
Definition ssl_common.h:655
char * locked_cn
Our locked common name, username, and cert hashes (cannot change during the life of this tls_multi ob...
Definition ssl_common.h:644
bool use_peer_id
Definition ssl_common.h:701
char * locked_original_username
The username that client initially used before being overridden by –override-user.
Definition ssl_common.h:653
uint32_t rx_peer_id
Definition ssl_common.h:699
int dco_peer_id
This is the handle that DCO uses to identify this session with the kernel.
Definition ssl_common.h:725
bool data_epoch_supported
whether our underlying data channel supports new data channel features (epoch keys with AEAD tag at t...
Definition ssl_common.h:379
Security parameter state of a single session within a VPN tunnel.
Definition ssl_common.h:489
struct key_state key[KS_SIZE]
Definition ssl_common.h:524
struct tls_options * opt
Definition ssl_common.h:491
in_addr_t local
Definition tun.h:208
struct in6_addr local_ipv6
Definition tun.h:211
dco_context_t dco
Definition tun.h:247
in_addr_t remote_netmask
Definition tun.h:209
char username[USER_PASS_LEN]
Definition misc.h:70
#define SIGHUP
Definition syshead.h:55
#define SIGINT
Definition syshead.h:56
#define SIGTERM
Definition syshead.h:59
#define SIGUSR1
Definition syshead.h:57
uint32_t in_addr_t
Definition syshead.h:52
#define SIGUSR2
Definition syshead.h:58
static int cleanup(void **state)
struct gc_arena gc
Definition test_ssl.c:122
int dev_type_enum(const char *dev, const char *dev_type)
Definition tun.c:521
#define TUNNEL_TOPOLOGY(tt)
Definition tun.h:185
#define TUNNEL_TYPE(tt)
Definition tun.h:182
int16_t vlan_decapsulate(const struct context *c, struct buffer *buf)
Definition vlan.c:81
bool vlan_is_tagged(const struct buffer *buf)
Definition vlan.c:261