X-Git-Url: http://git.archive.openwrt.org/?p=project%2Frelayd.git;a=blobdiff_plain;f=main.c;h=b3c13f7f7a49f3693df2efa1adfcae8dbaba56cf;hp=48c594e47a9243c5a2dc2f6979bd14fdd8350712;hb=refs%2Fheads%2Fmaster;hpb=b4ba9ff8cb2ed0283ffb05b13d1da0d93f09957a diff --git a/main.c b/main.c index 48c594e..b3c13f7 100644 --- a/main.c +++ b/main.c @@ -31,13 +31,25 @@ #include "relayd.h" +static LIST_HEAD(pending_routes); LIST_HEAD(interfaces); int debug; static int host_timeout; +static int host_ping_tries; static int inet_sock; static int forward_bcast; static int forward_dhcp; +static int parse_dhcp; + +uint8_t local_addr[4]; +int local_route_table; + +struct relayd_pending_route { + struct relayd_route rt; + struct uloop_timeout timeout; + uint8_t gateway[4]; +}; static struct relayd_host *find_host_by_ipaddr(struct relayd_interface *rif, const uint8_t *ipaddr) { @@ -81,19 +93,55 @@ static void add_arp(struct relayd_host *host) ioctl(inet_sock, SIOCSARP, &arp); } +static void timeout_host_route(struct uloop_timeout *timeout) +{ + struct relayd_pending_route *rt; + + rt = container_of(timeout, struct relayd_pending_route, timeout); + list_del(&rt->rt.list); + free(rt); +} + +void relayd_add_host_route(struct relayd_host *host, const uint8_t *dest, uint8_t mask) +{ + struct relayd_route *rt; + + list_for_each_entry(rt, &host->routes, list) { + if (!memcmp(rt->dest, dest, sizeof(rt->dest)) && rt->mask == mask) + return; + } + + rt = calloc(1, sizeof(*rt)); + if (!rt) + return; + + list_add(&rt->list, &host->routes); + memcpy(rt->dest, dest, sizeof(rt->dest)); + rt->mask = mask; + relayd_add_route(host, rt); +} + static void del_host(struct relayd_host *host) { + struct relayd_route *route, *tmp; + DPRINTF(1, "%s: deleting host "IP_FMT" ("MAC_FMT")\n", host->rif->ifname, IP_BUF(host->ipaddr), MAC_BUF(host->lladdr)); + list_for_each_entry_safe(route, tmp, &host->routes, list) { + relayd_del_route(host, route); + list_del(&route->list); + free(route); + } if (host->rif->managed) - relayd_del_route(host); + relayd_del_route(host, NULL); + uloop_timeout_cancel(&host->timeout); list_del(&host->list); free(host); } -static void fill_arp_request(struct arp_packet *pkt, struct relayd_interface *rif, - uint8_t spa[4], uint8_t tpa[4]) +static void fill_arp_packet(struct arp_packet *pkt, struct relayd_interface *rif, + const uint8_t spa[4], const uint8_t tpa[4]) { memset(pkt, 0, sizeof(*pkt)); @@ -110,15 +158,14 @@ static void fill_arp_request(struct arp_packet *pkt, struct relayd_interface *ri pkt->arp.arp_pln = 4; } -static void send_arp_request(struct relayd_host *host) +static void send_arp_request(struct relayd_interface *rif, const uint8_t *ipaddr) { - struct relayd_interface *rif = host->rif; struct arp_packet pkt; - fill_arp_request(&pkt, host->rif, host->rif->src_ip, host->ipaddr); + fill_arp_packet(&pkt, rif, rif->src_ip, ipaddr); pkt.arp.arp_op = htons(ARPOP_REQUEST); - memcpy(pkt.arp.arp_spa, rif->src_ip, ETH_ALEN); + memcpy(pkt.arp.arp_spa, rif->src_ip, sizeof(pkt.arp.arp_spa)); memset(pkt.arp.arp_tha, 0, ETH_ALEN); memset(pkt.eth.ether_dhost, 0xff, ETH_ALEN); @@ -130,28 +177,83 @@ static void send_arp_request(struct relayd_host *host) (struct sockaddr *) &rif->sll, sizeof(rif->sll)); } -static void send_arp_reply(struct relayd_interface *rif, uint8_t spa[4], - uint8_t tha[ETH_ALEN], uint8_t tpa[4]) +void relayd_add_pending_route(const uint8_t *gateway, const uint8_t *dest, uint8_t mask, int timeout) +{ + struct relayd_pending_route *rt; + struct relayd_interface *rif; + struct relayd_host *host; + + host = find_host_by_ipaddr(NULL, gateway); + if (host) { + relayd_add_host_route(host, dest, mask); + return; + } + + rt = calloc(1, sizeof(*rt)); + if (!rt) + return; + + memcpy(rt->gateway, gateway, sizeof(rt->gateway)); + memcpy(rt->rt.dest, dest, sizeof(rt->rt.dest)); + rt->rt.mask = mask; + list_add(&rt->rt.list, &pending_routes); + if (timeout <= 0) + return; + + rt->timeout.cb = timeout_host_route; + uloop_timeout_set(&rt->timeout, 10000); + list_for_each_entry(rif, &interfaces, list) { + send_arp_request(rif, gateway); + } +} + +static void send_arp_reply(struct relayd_interface *rif, const uint8_t spa[4], + const uint8_t tha[ETH_ALEN], const uint8_t tpa[4]) { struct arp_packet pkt; - fill_arp_request(&pkt, rif, spa, tpa); + fill_arp_packet(&pkt, rif, spa, tpa); - pkt.arp.arp_op = htons(ARPOP_REPLY); - memcpy(pkt.eth.ether_dhost, tha, ETH_ALEN); - memcpy(pkt.arp.arp_tha, tha, ETH_ALEN); + if (tha) { + pkt.arp.arp_op = htons(ARPOP_REPLY); + memcpy(pkt.eth.ether_dhost, tha, ETH_ALEN); + memcpy(pkt.arp.arp_tha, tha, ETH_ALEN); - DPRINTF(2, "%s: sending ARP reply to "IP_FMT", "IP_FMT" is at ("MAC_FMT")\n", - rif->ifname, IP_BUF(pkt.arp.arp_tpa), - IP_BUF(pkt.arp.arp_spa), MAC_BUF(pkt.eth.ether_shost)); + DPRINTF(2, "%s: sending ARP reply to "IP_FMT", "IP_FMT" is at ("MAC_FMT")\n", + rif->ifname, IP_BUF(pkt.arp.arp_tpa), + IP_BUF(pkt.arp.arp_spa), MAC_BUF(pkt.eth.ether_shost)); + } else { + pkt.arp.arp_op = htons(ARPOP_REQUEST); + memset(pkt.eth.ether_dhost, 0xff, ETH_ALEN); + memset(pkt.arp.arp_tha, 0xff, ETH_ALEN); + + DPRINTF(2, "%s: sending gratuitous ARP: "IP_FMT" is at ("MAC_FMT")\n", + rif->ifname, IP_BUF(pkt.arp.arp_tpa), + MAC_BUF(pkt.eth.ether_shost)); + } + + sendto(rif->fd.fd, &pkt, sizeof(pkt), 0, + (struct sockaddr *) &rif->sll, sizeof(rif->sll)); + + if (tha) + return; + + /* + * Gratuitous ARP comes in two flavours, request and reply. + * Some operating systems only accept request, some only reply. + * Let's just send both... + */ + pkt.arp.arp_op = htons(ARPOP_REPLY); sendto(rif->fd.fd, &pkt, sizeof(pkt), 0, (struct sockaddr *) &rif->sll, sizeof(rif->sll)); + } static void host_entry_timeout(struct uloop_timeout *timeout) { struct relayd_host *host = container_of(timeout, struct relayd_host, timeout); + struct relayd_interface *rif; /* * When a host is behind a managed interface, we must not expire its host @@ -160,8 +262,10 @@ static void host_entry_timeout(struct uloop_timeout *timeout) * When the timeout is reached, try pinging the host a few times before * giving up on it. */ - if (host->rif->managed && host->cleanup_pending < 2) { - send_arp_request(host); + if (host->rif->managed && host->cleanup_pending < host_ping_tries) { + list_for_each_entry(rif, &interfaces, list) { + send_arp_request(rif, host->ipaddr); + } host->cleanup_pending++; uloop_timeout_set(&host->timeout, 1000); return; @@ -172,11 +276,13 @@ static void host_entry_timeout(struct uloop_timeout *timeout) static struct relayd_host *add_host(struct relayd_interface *rif, const uint8_t *lladdr, const uint8_t *ipaddr) { struct relayd_host *host; + struct relayd_pending_route *route, *rtmp; DPRINTF(1, "%s: adding host "IP_FMT" ("MAC_FMT")\n", rif->ifname, IP_BUF(ipaddr), MAC_BUF(lladdr)); host = calloc(1, sizeof(*host)); + INIT_LIST_HEAD(&host->routes); host->rif = rif; memcpy(host->ipaddr, ipaddr, sizeof(host->ipaddr)); memcpy(host->lladdr, lladdr, sizeof(host->lladdr)); @@ -186,11 +292,37 @@ static struct relayd_host *add_host(struct relayd_interface *rif, const uint8_t add_arp(host); if (rif->managed) - relayd_add_route(host); + relayd_add_route(host, NULL); + + list_for_each_entry_safe(route, rtmp, &pending_routes, rt.list) { + if (memcmp(route->gateway, ipaddr, 4) != 0) + continue; + + relayd_add_host_route(host, route->rt.dest, route->rt.mask); + if (!route->timeout.pending) + continue; + + uloop_timeout_cancel(&route->timeout); + list_del(&route->rt.list); + free(route); + } return host; } +static void send_gratuitous_arp(struct relayd_interface *rif, const uint8_t *spa) +{ + struct relayd_interface *to_rif; + + list_for_each_entry(to_rif, &interfaces, list) { + if (rif == to_rif) + continue; + + send_arp_reply(to_rif, spa, NULL, spa); + } +} + + struct relayd_host *relayd_refresh_host(struct relayd_interface *rif, const uint8_t *lladdr, const uint8_t *ipaddr) { struct relayd_host *host; @@ -206,13 +338,16 @@ struct relayd_host *relayd_refresh_host(struct relayd_interface *rif, const uint * If the old entry is behind a managed interface, it will be pinged * before we expire it */ - if (host && !host->cleanup_pending) + if (host && !host->cleanup_pending) { uloop_timeout_set(&host->timeout, 1); + return NULL; + } host = add_host(rif, lladdr, ipaddr); } else { host->cleanup_pending = false; uloop_timeout_set(&host->timeout, host_timeout * 1000); + send_gratuitous_arp(rif, ipaddr); } return host; @@ -229,7 +364,9 @@ static void relay_arp_request(struct relayd_interface *from_rif, struct arp_pack continue; memcpy(reqpkt.eth.ether_shost, rif->sll.sll_addr, ETH_ALEN); + memset(reqpkt.eth.ether_dhost, 0xff, ETH_ALEN); memcpy(reqpkt.arp.arp_sha, rif->sll.sll_addr, ETH_ALEN); + memset(reqpkt.arp.arp_tha, 0, ETH_ALEN); DPRINTF(2, "%s: sending ARP who-has "IP_FMT", tell "IP_FMT" ("MAC_FMT")\n", rif->ifname, IP_BUF(reqpkt.arp.arp_tpa), @@ -253,7 +390,14 @@ static void recv_arp_request(struct relayd_interface *rif, struct arp_packet *pk if (!memcmp(pkt->arp.arp_spa, "\x00\x00\x00\x00", 4)) return; - relayd_refresh_host(rif, pkt->eth.ether_shost, pkt->arp.arp_spa); + host = find_host_by_ipaddr(NULL, pkt->arp.arp_spa); + if (!host || host->rif != rif) + relayd_refresh_host(rif, pkt->eth.ether_shost, pkt->arp.arp_spa); + + if (local_route_table && !memcmp(pkt->arp.arp_tpa, local_addr, sizeof(local_addr))) { + send_arp_reply(rif, local_addr, pkt->arp.arp_sha, pkt->arp.arp_spa); + return; + } host = find_host_by_ipaddr(NULL, pkt->arp.arp_tpa); @@ -269,7 +413,6 @@ static void recv_arp_request(struct relayd_interface *rif, struct arp_packet *pk relay_arp_request(rif, pkt); } - static void recv_arp_reply(struct relayd_interface *rif, struct arp_packet *pkt) { struct relayd_host *host; @@ -280,10 +423,8 @@ static void recv_arp_reply(struct relayd_interface *rif, struct arp_packet *pkt) MAC_BUF(pkt->eth.ether_shost), IP_BUF(pkt->arp.arp_tpa)); - relayd_refresh_host(rif, pkt->arp.arp_sha, pkt->arp.arp_spa); - - if (!memcmp(pkt->arp.arp_tpa, rif->src_ip, 4)) - return; + if (memcmp(pkt->arp.arp_sha, rif->sll.sll_addr, ETH_ALEN) != 0) + relayd_refresh_host(rif, pkt->arp.arp_sha, pkt->arp.arp_spa); host = find_host_by_ipaddr(NULL, pkt->arp.arp_tpa); if (!host) @@ -328,7 +469,7 @@ static void recv_packet(struct uloop_fd *fd, unsigned int events) } while (1); } -static void forward_bcast_packet(struct relayd_interface *from_rif, void *packet, int len) +void relayd_forward_bcast_packet(struct relayd_interface *from_rif, void *packet, int len) { struct relayd_interface *rif; struct ether_header *eth = packet; @@ -343,86 +484,6 @@ static void forward_bcast_packet(struct relayd_interface *from_rif, void *packet } } -static uint16_t -chksum(uint16_t sum, const uint8_t *data, uint16_t len) -{ - const uint8_t *last; - uint16_t t; - - last = data + len - 1; - - while(data < last) { - t = (data[0] << 8) + data[1]; - sum += t; - if(sum < t) - sum++; - data += 2; - } - - if(data == last) { - t = (data[0] << 8) + 0; - sum += t; - if(sum < t) - sum++; - } - - return sum; -} - -static bool forward_dhcp_packet(struct relayd_interface *rif, void *data, int len) -{ - struct ip_packet *pkt = data; - struct udphdr *udp; - struct dhcp_header *dhcp; - int udplen; - uint16_t sum; - - if (pkt->eth.ether_type != htons(ETH_P_IP)) - return false; - - if (pkt->iph.version != 4) - return false; - - if (pkt->iph.protocol != IPPROTO_UDP) - return false; - - udp = (void *) ((char *) &pkt->iph + (pkt->iph.ihl << 2)); - dhcp = (void *) (udp + 1); - - udplen = ntohs(udp->len); - if (udplen > len - ((char *) udp - (char *) data)) - return false; - - if (udp->dest != htons(67) && udp->source != htons(67)) - return false; - - if (dhcp->op != 1 && dhcp->op != 2) - return false; - - if (!forward_dhcp) - return true; - - if (dhcp->op == 2) - relayd_refresh_host(rif, pkt->eth.ether_shost, (void *) &pkt->iph.saddr); - - DPRINTF(2, "%s: handling DHCP %s\n", rif->ifname, (dhcp->op == 1 ? "request" : "response")); - - dhcp->flags |= htons(DHCP_FLAG_BROADCAST); - - udp->check = 0; - sum = udplen + IPPROTO_UDP; - sum = chksum(sum, (void *) &pkt->iph.saddr, 8); - sum = chksum(sum, (void *) udp, udplen); - if (sum == 0) - sum = 0xffff; - - udp->check = htons(~sum); - - forward_bcast_packet(rif, data, len); - - return true; -} - static void recv_bcast_packet(struct uloop_fd *fd, unsigned int events) { struct relayd_interface *rif = container_of(fd, struct relayd_interface, bcast_fd); @@ -447,11 +508,11 @@ static void recv_bcast_packet(struct uloop_fd *fd, unsigned int events) if (!forward_bcast && !forward_dhcp) continue; - if (forward_dhcp_packet(rif, pktbuf, pktlen)) + if (relayd_handle_dhcp_packet(rif, pktbuf, pktlen, forward_dhcp, parse_dhcp)) continue; if (forward_bcast) - forward_bcast_packet(rif, pktbuf, pktlen); + relayd_forward_bcast_packet(rif, pktbuf, pktlen); } while (1); } @@ -529,14 +590,25 @@ static int init_interface(struct relayd_interface *rif) } #ifdef PACKET_RECV_TYPE - pkt_type = (1 << PACKET_BROADCAST); + pkt_type = (1 << PACKET_BROADCAST) | (1 << PACKET_MULTICAST); setsockopt(fd, SOL_PACKET, PACKET_RECV_TYPE, &pkt_type, sizeof(pkt_type)); #endif uloop_fd_add(&rif->bcast_fd, ULOOP_READ | ULOOP_EDGE_TRIGGER); + relayd_add_interface_routes(rif); return 0; } +static void ping_static_routes(void) +{ + struct relayd_pending_route *rt; + struct relayd_interface *rif; + + list_for_each_entry(rt, &pending_routes, rt.list) + list_for_each_entry(rif, &interfaces, list) + send_arp_request(rif, rt->gateway); +} + static int init_interfaces(void) { struct relayd_interface *rif; @@ -551,43 +623,51 @@ static int init_interfaces(void) return 0; } -static void del_interface(struct relayd_interface *rif) +static void cleanup_hosts(void) { - struct relayd_host *host, *htmp; + struct relayd_interface *rif; + struct relayd_host *host, *tmp; - list_for_each_entry_safe(host, htmp, &rif->hosts, list) { - del_host(host); + list_for_each_entry(rif, &interfaces, list) { + list_for_each_entry_safe(host, tmp, &rif->hosts, list) { + del_host(host); + } } - free(rif); } -static void cleanup_interfaces(void) +static void free_interfaces(void) { struct relayd_interface *rif, *rtmp; list_for_each_entry_safe(rif, rtmp, &interfaces, list) { - del_interface(rif); + relayd_del_interface_routes(rif); + list_del(&rif->list); + free(rif); } } -static int alloc_interface(const char *ifname, bool managed) +static struct relayd_interface *alloc_interface(const char *ifname, bool managed) { struct relayd_interface *rif; if (strlen(ifname) >= IFNAMSIZ) - return -1; + return NULL; + + list_for_each_entry(rif, &interfaces, list) { + if (!strncmp(rif->ifname, ifname, IFNAMSIZ)) + return rif; + } rif = calloc(1, sizeof(*rif)); if (!rif) - return -1; + return NULL; - INIT_LIST_HEAD(&rif->list); INIT_LIST_HEAD(&rif->hosts); strcpy(rif->ifname, ifname); list_add(&rif->list, &interfaces); rif->managed = managed; - return 0; + return rif; } static void die(int signo) @@ -596,8 +676,7 @@ static void die(int signo) * When we hit SIGTERM, clean up interfaces directly, so that we * won't leave our routing in an invalid state. */ - cleanup_interfaces(); - exit(1); + uloop_end(); } static int usage(const char *progname) @@ -609,9 +688,16 @@ static int usage(const char *progname) " -i Add an interface for relaying\n" " -I Same as -i, except with ARP cache and host route management\n" " You need to specify at least two interfaces\n" + " -G Set a gateway IP for clients\n" + " -R :/\n" + " Add a static route for / via \n" " -t Host entry expiry timeout\n" + " -p Number of ARP ping attempts before considering a host dead\n" + " -T Set routing table number for automatically added routes\n" " -B Enable broadcast forwarding\n" " -D Enable DHCP forwarding\n" + " -P Disable DHCP options parsing\n" + " -L Enable local access using as source address\n" "\n", progname); return -1; @@ -619,8 +705,13 @@ static int usage(const char *progname) int main(int argc, char **argv) { - bool managed; + struct relayd_interface *rif = NULL; + struct in_addr addr, addr2; + bool local_addr_valid = false; + bool managed = false; int ifnum = 0; + char *s, *s2; + int mask; int ch; debug = 0; @@ -630,18 +721,22 @@ int main(int argc, char **argv) return 1; } - host_timeout = 60; + host_timeout = 30; + host_ping_tries = 5; forward_bcast = 0; + local_route_table = 0; + parse_dhcp = 1; uloop_init(); - while ((ch = getopt(argc, argv, "I:i:t:BDd")) != -1) { + while ((ch = getopt(argc, argv, "I:i:t:p:BDPdT:G:R:L:")) != -1) { switch(ch) { case 'I': managed = true; /* fall through */ case 'i': ifnum++; - if (alloc_interface(optarg, managed) < 0) + rif = alloc_interface(optarg, managed); + if (!rif) return 1; managed = false; @@ -651,6 +746,11 @@ int main(int argc, char **argv) if (host_timeout <= 0) return usage(argv[0]); break; + case 'p': + host_ping_tries = atoi(optarg); + if (host_ping_tries <= 0) + return usage(argv[0]); + break; case 'd': debug++; break; @@ -660,6 +760,56 @@ int main(int argc, char **argv) case 'D': forward_dhcp = 1; break; + case 'P': + parse_dhcp = 0; + break; + case 'T': + route_table = atoi(optarg); + if (route_table <= 0) + return usage(argv[0]); + break; + case 'G': + if (!inet_aton(optarg, &addr)) { + fprintf(stderr, "Address '%s' not found\n", optarg); + return 1; + } + relayd_add_pending_route((uint8_t *) &addr.s_addr, (const uint8_t *) "\x00\x00\x00\x00", 0, 0); + break; + case 'L': + if (!inet_aton(optarg, &addr)) { + fprintf(stderr, "Address '%s' not found\n", optarg); + return 1; + } + memcpy(&local_addr, &addr.s_addr, sizeof(local_addr)); + local_addr_valid = true; + break; + case 'R': + s = strchr(optarg, ':'); + if (!s) + return usage(argv[0]); + + *(s++) = 0; + if (!inet_aton(optarg, &addr)) { + fprintf(stderr, "Address '%s' not found\n", optarg); + return 1; + } + + s2 = strchr(s, '/'); + if (!s2) + return usage(argv[0]); + + *(s2++) = 0; + if (!inet_aton(s, &addr2)) { + fprintf(stderr, "Address '%s' not found\n", s); + return 1; + } + + mask = atoi(s2); + if (mask < 0 || mask > 32) + return usage(argv[0]); + + relayd_add_pending_route((uint8_t *) &addr.s_addr, (uint8_t *) &addr2.s_addr, mask, 0); + break; case '?': default: return usage(argv[0]); @@ -682,16 +832,22 @@ int main(int argc, char **argv) signal(SIGUSR1, die); signal(SIGUSR2, die); - if (init_interfaces() < 0) - return 1; + if (local_addr_valid) + local_route_table = route_table++; if (relayd_rtnl_init() < 0) return 1; + if (init_interfaces() < 0) + return 1; + + ping_static_routes(); + uloop_run(); uloop_done(); - cleanup_interfaces(); + cleanup_hosts(); + free_interfaces(); relayd_rtnl_done(); close(inet_sock);