]> Cypherpunks.ru repositories - govpn.git/blob - cmd/govpn-server/main.go
1ce5a3748cd02d391f311f64adb6c090c0eaee84
[govpn.git] / cmd / govpn-server / main.go
1 /*
2 GoVPN -- simple secure free software virtual private network daemon
3 Copyright (C) 2014-2015 Sergey Matveev <stargrave@stargrave.org>
4
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation, either version 3 of the License, or
8 (at your option) any later version.
9
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
13 GNU General Public License for more details.
14
15 You should have received a copy of the GNU General Public License
16 along with this program.  If not, see <http://www.gnu.org/licenses/>.
17 */
18
19 // Simple secure free software virtual private network daemon.
20 package main
21
22 import (
23         "bytes"
24         "flag"
25         "log"
26         "net"
27         "os"
28         "os/signal"
29         "path"
30         "time"
31
32         "govpn"
33 )
34
35 var (
36         bindAddr  = flag.String("bind", "[::]:1194", "Bind to address")
37         peersPath = flag.String("peers", "peers", "Path to peers keys directory")
38         mtu       = flag.Int("mtu", 1500, "MTU")
39         nonceDiff = flag.Int("noncediff", 1, "Allow nonce difference")
40         timeoutP  = flag.Int("timeout", 60, "Timeout seconds")
41 )
42
43 type PeerReadyEvent struct {
44         peer  *govpn.Peer
45         iface string
46 }
47
48 type PeerState struct {
49         peer      *govpn.Peer
50         tap       *govpn.TAP
51         sink      chan []byte
52         ready     chan struct{}
53         terminate chan struct{}
54 }
55
56 func NewPeerState(peer *govpn.Peer, iface string) *PeerState {
57         tap, sink, ready, terminate, err := govpn.TAPListen(iface)
58         if err != nil {
59                 log.Println("Unable to create Eth", err)
60                 return nil
61         }
62         state := PeerState{
63                 peer:      peer,
64                 tap:       tap,
65                 sink:      sink,
66                 ready:     ready,
67                 terminate: terminate,
68         }
69         return &state
70 }
71
72 type EthEvent struct {
73         peer  *govpn.Peer
74         data  []byte
75         ready chan struct{}
76 }
77
78 func main() {
79         flag.Parse()
80         timeout := time.Second * time.Duration(*timeoutP)
81         var err error
82         log.SetFlags(log.Ldate | log.Lmicroseconds | log.Lshortfile)
83
84         govpn.MTU = *mtu
85         govpn.Timeout = *timeoutP
86         govpn.Noncediff = *nonceDiff
87         govpn.PeersInit(*peersPath)
88
89         bind, err := net.ResolveUDPAddr("udp", *bindAddr)
90         if err != nil {
91                 panic(err)
92         }
93         conn, err := net.ListenUDP("udp", bind)
94         if err != nil {
95                 panic(err)
96         }
97         udpSink, udpBuf, udpReady := govpn.ConnListen(conn)
98
99         termSignal := make(chan os.Signal, 1)
100         signal.Notify(termSignal, os.Interrupt, os.Kill)
101
102         hsHeartbeat := time.Tick(timeout)
103         go func() { <-hsHeartbeat }()
104
105         var addr string
106         var state *govpn.Handshake
107         var peerState *PeerState
108         var peer *govpn.Peer
109         var exists bool
110         states := make(map[string]*govpn.Handshake)
111         peers := make(map[string]*PeerState)
112         peerReadySink := make(chan PeerReadyEvent)
113         var peerReady PeerReadyEvent
114         var udpPkt *govpn.UDPPkt
115         var udpPktData []byte
116         var ethEvent EthEvent
117         ethSink := make(chan EthEvent)
118
119         log.Println("Server version", govpn.Version)
120         log.Println("Server started")
121
122 MainCycle:
123         for {
124                 select {
125                 case <-termSignal:
126                         break MainCycle
127                 case <-hsHeartbeat:
128                         now := time.Now()
129                         for addr, hs := range states {
130                                 if hs.LastPing.Add(timeout).Before(now) {
131                                         log.Println("Deleting handshake state", addr)
132                                         hs.Zero()
133                                         delete(states, addr)
134                                 }
135                         }
136                         for addr, state := range peers {
137                                 if state.peer.LastPing.Add(timeout).Before(now) {
138                                         log.Println("Deleting peer", state.peer)
139                                         delete(peers, addr)
140                                         downPath := path.Join(
141                                                 govpn.PeersPath,
142                                                 state.peer.Id.String(),
143                                                 "down.sh",
144                                         )
145                                         go govpn.ScriptCall(downPath, state.tap.Name)
146                                         state.terminate <- struct{}{}
147                                         state.peer.Zero()
148                                 }
149                         }
150                 case peerReady = <-peerReadySink:
151                         for addr, state := range peers {
152                                 if state.tap.Name != peerReady.iface {
153                                         continue
154                                 }
155                                 delete(peers, addr)
156                                 state.terminate <- struct{}{}
157                                 state.peer.Zero()
158                                 break
159                         }
160                         addr = peerReady.peer.Addr.String()
161                         state := NewPeerState(peerReady.peer, peerReady.iface)
162                         if state == nil {
163                                 continue
164                         }
165                         peers[addr] = state
166                         states[addr].Zero()
167                         delete(states, addr)
168                         log.Println("Registered interface", peerReady.iface, "with peer", peer)
169                         go func(state *PeerState) {
170                                 for data := range state.sink {
171                                         ethSink <- EthEvent{
172                                                 peer:  state.peer,
173                                                 data:  data,
174                                                 ready: state.ready,
175                                         }
176                                 }
177                         }(state)
178                 case ethEvent = <-ethSink:
179                         if s, exists := peers[ethEvent.peer.Addr.String()]; !exists || s.peer != ethEvent.peer {
180                                 continue
181                         }
182                         ethEvent.peer.EthProcess(ethEvent.data, conn, ethEvent.ready)
183                 case udpPkt = <-udpSink:
184                         if udpPkt == nil {
185                                 udpReady <- struct{}{}
186                                 continue
187                         }
188                         udpPktData = udpBuf[:udpPkt.Size]
189                         addr = udpPkt.Addr.String()
190                         if govpn.IsValidHandshakePkt(udpPktData) {
191                                 state, exists = states[addr]
192                                 if !exists {
193                                         state = govpn.HandshakeNew(udpPkt.Addr)
194                                         states[addr] = state
195                                 }
196                                 peer = state.Server(conn, udpPktData)
197                                 if peer != nil {
198                                         log.Println("Peer handshake finished", peer)
199                                         if _, exists = peers[addr]; exists {
200                                                 go func() {
201                                                         peerReadySink <- PeerReadyEvent{peer, peers[addr].tap.Name}
202                                                 }()
203                                         } else {
204                                                 go func() {
205                                                         upPath := path.Join(govpn.PeersPath, peer.Id.String(), "up.sh")
206                                                         result, err := govpn.ScriptCall(upPath, "")
207                                                         if err != nil {
208                                                                 return
209                                                         }
210                                                         sepIndex := bytes.Index(result, []byte{'\n'})
211                                                         if sepIndex < 0 {
212                                                                 sepIndex = len(result)
213                                                         }
214                                                         ifaceName := string(result[:sepIndex])
215                                                         peerReadySink <- PeerReadyEvent{peer, ifaceName}
216                                                 }()
217                                         }
218                                 }
219                                 udpReady <- struct{}{}
220                                 continue
221                         }
222                         peerState, exists = peers[addr]
223                         if !exists {
224                                 udpReady <- struct{}{}
225                                 continue
226                         }
227                         peerState.peer.UDPProcess(udpPktData, peerState.tap, udpReady)
228                 }
229         }
230 }