2015-01-22 00:55:44 +01:00
|
|
|
/*
|
|
|
|
* Tunala ("Tunneler with a New Zealand accent") Written by Geoff Thorpe,
|
|
|
|
* but endorsed/supported by noone. Please use this is if it's useful or
|
|
|
|
* informative to you, but it's only here as a scratchpad for ideas about how
|
|
|
|
* you might (or might not) program with OpenSSL. If you deploy this is in a
|
|
|
|
* mission-critical environment, and have not read, understood, audited, and
|
|
|
|
* modified this code to your satisfaction, and the result is that all hell
|
|
|
|
* breaks loose and you are looking for a new employer, then it proves
|
|
|
|
* nothing except perhaps that Darwinism is alive and well. Let's just say,
|
|
|
|
* *I* don't use this in a mission-critical environment, so it would be
|
|
|
|
* stupid for anyone to assume that it is solid and/or tested enough when
|
|
|
|
* even its author doesn't place that much trust in it. You have been warned.
|
2000-11-02 00:11:19 +01:00
|
|
|
* With thanks to Cryptographic Appliances, Inc.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef _TUNALA_H
|
2015-01-22 00:55:44 +01:00
|
|
|
# define _TUNALA_H
|
2000-11-02 00:11:19 +01:00
|
|
|
|
2001-07-23 21:03:48 +02:00
|
|
|
/* pull in autoconf fluff */
|
2015-01-22 00:55:44 +01:00
|
|
|
# ifndef NO_CONFIG_H
|
|
|
|
# include "config.h"
|
|
|
|
# else
|
|
|
|
/*
|
|
|
|
* We don't have autoconf, we have to set all of these unless a tweaked
|
|
|
|
* Makefile tells us not to ...
|
|
|
|
*/
|
2001-07-23 21:03:48 +02:00
|
|
|
/* headers */
|
2015-01-22 00:55:44 +01:00
|
|
|
# ifndef NO_HAVE_SELECT
|
|
|
|
# define HAVE_SELECT
|
|
|
|
# endif
|
|
|
|
# ifndef NO_HAVE_SOCKET
|
|
|
|
# define HAVE_SOCKET
|
|
|
|
# endif
|
|
|
|
# ifndef NO_HAVE_UNISTD_H
|
|
|
|
# define HAVE_UNISTD_H
|
|
|
|
# endif
|
|
|
|
# ifndef NO_HAVE_FCNTL_H
|
|
|
|
# define HAVE_FCNTL_H
|
|
|
|
# endif
|
|
|
|
# ifndef NO_HAVE_LIMITS_H
|
|
|
|
# define HAVE_LIMITS_H
|
|
|
|
# endif
|
2001-07-23 21:03:48 +02:00
|
|
|
/* features */
|
2015-01-22 00:55:44 +01:00
|
|
|
# ifndef NO_HAVE_STRSTR
|
|
|
|
# define HAVE_STRSTR
|
|
|
|
# endif
|
|
|
|
# ifndef NO_HAVE_STRTOUL
|
|
|
|
# define HAVE_STRTOUL
|
|
|
|
# endif
|
|
|
|
# endif
|
|
|
|
|
|
|
|
# if !defined(HAVE_SELECT) || !defined(HAVE_SOCKET)
|
|
|
|
# error "can't build without some network basics like select() and socket()"
|
|
|
|
# endif
|
|
|
|
|
|
|
|
# include <stdlib.h>
|
|
|
|
# ifndef NO_SYSTEM_H
|
|
|
|
# include <string.h>
|
|
|
|
# ifdef HAVE_UNISTD_H
|
|
|
|
# include <unistd.h>
|
|
|
|
# endif
|
|
|
|
# ifdef HAVE_FCNTL_H
|
|
|
|
# include <fcntl.h>
|
|
|
|
# endif
|
|
|
|
# ifdef HAVE_LIMITS_H
|
|
|
|
# include <limits.h>
|
|
|
|
# endif
|
|
|
|
# include <netdb.h>
|
|
|
|
# include <signal.h>
|
|
|
|
# include <sys/socket.h>
|
|
|
|
# include <sys/types.h>
|
|
|
|
# include <netinet/in.h>
|
|
|
|
# endif /* !defined(NO_SYSTEM_H) */
|
|
|
|
|
|
|
|
# ifndef NO_OPENSSL
|
|
|
|
# include <openssl/err.h>
|
|
|
|
# include <openssl/engine.h>
|
|
|
|
# include <openssl/ssl.h>
|
|
|
|
# endif /* !defined(NO_OPENSSL) */
|
|
|
|
|
|
|
|
# ifndef OPENSSL_NO_BUFFER
|
|
|
|
/*
|
|
|
|
* This is the generic "buffer" type that is used when feeding the
|
2000-11-02 00:11:19 +01:00
|
|
|
* state-machine. It's basically a FIFO with respect to the "adddata" &
|
2015-01-22 00:55:44 +01:00
|
|
|
* "takedata" type functions that operate on it.
|
|
|
|
*/
|
|
|
|
# define MAX_DATA_SIZE 16384
|
2000-11-02 00:11:19 +01:00
|
|
|
typedef struct _buffer_t {
|
2015-01-22 00:55:44 +01:00
|
|
|
unsigned char data[MAX_DATA_SIZE];
|
|
|
|
unsigned int used;
|
|
|
|
/*
|
|
|
|
* Statistical values - counts the total number of bytes read in and read
|
|
|
|
* out (respectively) since "buffer_init()"
|
|
|
|
*/
|
|
|
|
unsigned long total_in, total_out;
|
2000-11-02 00:11:19 +01:00
|
|
|
} buffer_t;
|
|
|
|
|
|
|
|
/* Initialise a buffer structure before use */
|
2015-01-22 00:55:44 +01:00
|
|
|
void buffer_init(buffer_t * buf);
|
|
|
|
/*
|
|
|
|
* Cleanup a buffer structure - presently not needed, but if buffer_t is
|
|
|
|
* converted to using dynamic allocation, this would be required - so should
|
|
|
|
* be called to protect against an explosion of memory leaks later if the
|
|
|
|
* change is made.
|
|
|
|
*/
|
|
|
|
void buffer_close(buffer_t * buf);
|
2000-11-02 00:11:19 +01:00
|
|
|
|
|
|
|
/* Basic functions to manipulate buffers */
|
|
|
|
|
2015-01-22 00:55:44 +01:00
|
|
|
unsigned int buffer_used(buffer_t * buf); /* How much data in the buffer */
|
|
|
|
unsigned int buffer_unused(buffer_t * buf); /* How much space in the buffer */
|
|
|
|
int buffer_full(buffer_t * buf); /* Boolean, is it full? */
|
|
|
|
int buffer_notfull(buffer_t * buf); /* Boolean, is it not full? */
|
|
|
|
int buffer_empty(buffer_t * buf); /* Boolean, is it empty? */
|
|
|
|
int buffer_notempty(buffer_t * buf); /* Boolean, is it not empty? */
|
|
|
|
unsigned long buffer_total_in(buffer_t * buf); /* Total bytes written to
|
|
|
|
* buffer */
|
|
|
|
unsigned long buffer_total_out(buffer_t * buf); /* Total bytes read from
|
|
|
|
* buffer */
|
|
|
|
|
|
|
|
# if 0 /* Currently used only within buffer.c -
|
|
|
|
* better to expose only higher-level
|
|
|
|
* functions anyway */
|
|
|
|
/*
|
|
|
|
* Add data to the tail of the buffer, returns the amount that was actually
|
|
|
|
* added (so, you need to check if return value is less than size)
|
|
|
|
*/
|
|
|
|
unsigned int buffer_adddata(buffer_t * buf, const unsigned char *ptr,
|
|
|
|
unsigned int size);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Take data from the front of the buffer (and scroll the rest forward). If
|
2000-11-02 00:11:19 +01:00
|
|
|
* "ptr" is NULL, this just removes data off the front of the buffer. Return
|
2015-01-22 00:55:44 +01:00
|
|
|
* value is the amount actually removed (can be less than size if the buffer
|
|
|
|
* has too little data).
|
|
|
|
*/
|
|
|
|
unsigned int buffer_takedata(buffer_t * buf, unsigned char *ptr,
|
|
|
|
unsigned int size);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Flushes as much data as possible out of the "from" buffer into the "to"
|
|
|
|
* buffer. Return value is the amount moved. The amount moved can be
|
|
|
|
* restricted to a maximum by specifying "cap" - setting it to -1 means no
|
|
|
|
* limit.
|
|
|
|
*/
|
|
|
|
unsigned int buffer_tobuffer(buffer_t * to, buffer_t * from, int cap);
|
|
|
|
# endif
|
|
|
|
|
|
|
|
# ifndef NO_IP
|
2000-11-02 00:11:19 +01:00
|
|
|
/* Read or write between a file-descriptor and a buffer */
|
2015-01-22 00:55:44 +01:00
|
|
|
int buffer_from_fd(buffer_t * buf, int fd);
|
|
|
|
int buffer_to_fd(buffer_t * buf, int fd);
|
|
|
|
# endif /* !defined(NO_IP) */
|
2000-11-02 00:11:19 +01:00
|
|
|
|
2015-01-22 00:55:44 +01:00
|
|
|
# ifndef NO_OPENSSL
|
2000-11-02 00:11:19 +01:00
|
|
|
/* Read or write between an SSL or BIO and a buffer */
|
2015-01-22 00:55:44 +01:00
|
|
|
void buffer_from_SSL(buffer_t * buf, SSL *ssl);
|
|
|
|
void buffer_to_SSL(buffer_t * buf, SSL *ssl);
|
|
|
|
void buffer_from_BIO(buffer_t * buf, BIO *bio);
|
|
|
|
void buffer_to_BIO(buffer_t * buf, BIO *bio);
|
2000-11-29 00:27:23 +01:00
|
|
|
|
|
|
|
/* Callbacks */
|
2002-01-17 02:51:37 +01:00
|
|
|
void cb_ssl_info(const SSL *s, int where, int ret);
|
2015-01-21 22:22:49 +01:00
|
|
|
/* Called if output should be sent too */
|
|
|
|
void cb_ssl_info_set_output(FILE *fp);
|
2000-11-29 02:29:08 +01:00
|
|
|
int cb_ssl_verify(int ok, X509_STORE_CTX *ctx);
|
|
|
|
void cb_ssl_verify_set_output(FILE *fp);
|
2000-11-29 20:22:54 +01:00
|
|
|
void cb_ssl_verify_set_depth(unsigned int verify_depth);
|
2000-11-30 02:34:26 +01:00
|
|
|
void cb_ssl_verify_set_level(unsigned int level);
|
2002-02-20 06:02:50 +01:00
|
|
|
RSA *cb_generate_tmp_rsa(SSL *s, int is_export, int keylength);
|
2015-01-22 00:55:44 +01:00
|
|
|
# endif /* !defined(NO_OPENSSL) */
|
|
|
|
# endif /* !defined(OPENSSL_NO_BUFFER) */
|
2000-11-02 00:11:19 +01:00
|
|
|
|
2015-01-22 00:55:44 +01:00
|
|
|
# ifndef NO_TUNALA
|
|
|
|
# ifdef OPENSSL_NO_BUFFER
|
|
|
|
# error "TUNALA section of tunala.h requires BUFFER support"
|
|
|
|
# endif
|
2000-11-02 00:11:19 +01:00
|
|
|
typedef struct _state_machine_t {
|
2015-01-22 00:55:44 +01:00
|
|
|
SSL *ssl;
|
|
|
|
BIO *bio_intossl;
|
|
|
|
BIO *bio_fromssl;
|
|
|
|
buffer_t clean_in, clean_out;
|
|
|
|
buffer_t dirty_in, dirty_out;
|
2000-11-02 00:11:19 +01:00
|
|
|
} state_machine_t;
|
|
|
|
typedef enum {
|
2015-01-22 00:55:44 +01:00
|
|
|
SM_CLEAN_IN, SM_CLEAN_OUT,
|
|
|
|
SM_DIRTY_IN, SM_DIRTY_OUT
|
2000-11-02 00:11:19 +01:00
|
|
|
} sm_buffer_t;
|
2015-01-22 00:55:44 +01:00
|
|
|
void state_machine_init(state_machine_t * machine);
|
|
|
|
void state_machine_close(state_machine_t * machine);
|
|
|
|
buffer_t *state_machine_get_buffer(state_machine_t * machine,
|
|
|
|
sm_buffer_t type);
|
|
|
|
SSL *state_machine_get_SSL(state_machine_t * machine);
|
|
|
|
int state_machine_set_SSL(state_machine_t * machine, SSL *ssl, int is_server);
|
2000-11-02 00:11:19 +01:00
|
|
|
/* Performs the data-IO loop and returns zero if the machine should close */
|
2015-01-22 00:55:44 +01:00
|
|
|
int state_machine_churn(state_machine_t * machine);
|
|
|
|
/*
|
|
|
|
* Is used to handle closing conditions - namely when one side of the tunnel
|
|
|
|
* has closed but the other should finish flushing.
|
|
|
|
*/
|
|
|
|
int state_machine_close_clean(state_machine_t * machine);
|
|
|
|
int state_machine_close_dirty(state_machine_t * machine);
|
|
|
|
# endif /* !defined(NO_TUNALA) */
|
|
|
|
|
|
|
|
# ifndef NO_IP
|
|
|
|
/*
|
|
|
|
* Initialise anything related to the networking. This includes blocking
|
|
|
|
* pesky SIGPIPE signals.
|
|
|
|
*/
|
2000-11-02 00:11:19 +01:00
|
|
|
int ip_initialise(void);
|
2015-01-22 00:55:44 +01:00
|
|
|
/*
|
|
|
|
* ip is the 4-byte ip address (eg. 127.0.0.1 is {0x7F,0x00,0x00,0x01}), port
|
|
|
|
* is the port to listen on (host byte order), and the return value is the
|
|
|
|
* file-descriptor or -1 on error.
|
|
|
|
*/
|
2001-07-23 21:03:48 +02:00
|
|
|
int ip_create_listener_split(const char *ip, unsigned short port);
|
2000-11-02 00:11:19 +01:00
|
|
|
/* Same semantics as above. */
|
2001-07-23 21:03:48 +02:00
|
|
|
int ip_create_connection_split(const char *ip, unsigned short port);
|
2000-11-02 00:11:19 +01:00
|
|
|
/* Converts a string into the ip/port before calling the above */
|
|
|
|
int ip_create_listener(const char *address);
|
|
|
|
int ip_create_connection(const char *address);
|
2015-01-22 00:55:44 +01:00
|
|
|
/*
|
|
|
|
* Just does a string conversion on its own. NB: If accept_all_ip is
|
|
|
|
* non-zero, then the address string could be just a port. Ie. it's suitable
|
|
|
|
* for a listening address but not a connecting address.
|
|
|
|
*/
|
2001-07-23 21:03:48 +02:00
|
|
|
int ip_parse_address(const char *address, const char **parsed_ip,
|
2015-01-22 00:55:44 +01:00
|
|
|
unsigned short *port, int accept_all_ip);
|
|
|
|
/*
|
|
|
|
* Accepts an incoming connection through the listener. Assumes selects and
|
|
|
|
* what-not have deemed it an appropriate thing to do.
|
|
|
|
*/
|
2000-11-02 00:11:19 +01:00
|
|
|
int ip_accept_connection(int listen_fd);
|
2015-01-22 00:55:44 +01:00
|
|
|
# endif /* !defined(NO_IP) */
|
2000-11-02 00:11:19 +01:00
|
|
|
|
2001-07-23 21:03:48 +02:00
|
|
|
/* These functions wrap up things that can be portability hassles. */
|
|
|
|
int int_strtoul(const char *str, unsigned long *val);
|
2015-01-22 00:55:44 +01:00
|
|
|
# ifdef HAVE_STRSTR
|
|
|
|
# define int_strstr strstr
|
|
|
|
# else
|
2001-07-23 21:03:48 +02:00
|
|
|
char *int_strstr(const char *haystack, const char *needle);
|
2015-01-22 00:55:44 +01:00
|
|
|
# endif
|
2001-07-23 21:03:48 +02:00
|
|
|
|
2015-01-22 00:55:44 +01:00
|
|
|
#endif /* !defined(_TUNALA_H) */
|