]> Cypherpunks.ru repositories - govpn.git/blob - cmd/govpn-server/main.go
Optional HTTP-server providing with known peers information in JSON
[govpn.git] / cmd / govpn-server / main.go
1 /*
2 GoVPN -- simple secure free software virtual private network daemon
3 Copyright (C) 2014-2015 Sergey Matveev <stargrave@stargrave.org>
4
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation, either version 3 of the License, or
8 (at your option) any later version.
9
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
13 GNU General Public License for more details.
14
15 You should have received a copy of the GNU General Public License
16 along with this program.  If not, see <http://www.gnu.org/licenses/>.
17 */
18
19 // Simple secure free software virtual private network daemon.
20 package main
21
22 import (
23         "bytes"
24         "flag"
25         "log"
26         "net"
27         "os"
28         "os/signal"
29         "path"
30         "time"
31
32         "govpn"
33 )
34
35 var (
36         bindAddr  = flag.String("bind", "[::]:1194", "Bind to address")
37         peersPath = flag.String("peers", "peers", "Path to peers keys directory")
38         stats     = flag.String("stats", "", "Enable stats retrieving on host:port")
39         mtu       = flag.Int("mtu", 1500, "MTU")
40         nonceDiff = flag.Int("noncediff", 1, "Allow nonce difference")
41         timeoutP  = flag.Int("timeout", 60, "Timeout seconds")
42 )
43
44 type PeerReadyEvent struct {
45         peer  *govpn.Peer
46         iface string
47 }
48
49 type PeerState struct {
50         peer      *govpn.Peer
51         tap       *govpn.TAP
52         sink      chan []byte
53         ready     chan struct{}
54         terminate chan struct{}
55 }
56
57 func NewPeerState(peer *govpn.Peer, iface string) *PeerState {
58         tap, sink, ready, terminate, err := govpn.TAPListen(iface)
59         if err != nil {
60                 log.Println("Unable to create Eth", err)
61                 return nil
62         }
63         state := PeerState{
64                 peer:      peer,
65                 tap:       tap,
66                 sink:      sink,
67                 ready:     ready,
68                 terminate: terminate,
69         }
70         return &state
71 }
72
73 type EthEvent struct {
74         peer  *govpn.Peer
75         data  []byte
76         ready chan struct{}
77 }
78
79 func main() {
80         flag.Parse()
81         timeout := time.Second * time.Duration(*timeoutP)
82         var err error
83         log.SetFlags(log.Ldate | log.Lmicroseconds | log.Lshortfile)
84
85         govpn.MTU = *mtu
86         govpn.Timeout = *timeoutP
87         govpn.Noncediff = *nonceDiff
88         govpn.PeersInit(*peersPath)
89
90         bind, err := net.ResolveUDPAddr("udp", *bindAddr)
91         if err != nil {
92                 panic(err)
93         }
94         conn, err := net.ListenUDP("udp", bind)
95         if err != nil {
96                 panic(err)
97         }
98         udpSink, udpBuf, udpReady := govpn.ConnListen(conn)
99
100         termSignal := make(chan os.Signal, 1)
101         signal.Notify(termSignal, os.Interrupt, os.Kill)
102
103         hsHeartbeat := time.Tick(timeout)
104         go func() { <-hsHeartbeat }()
105
106         var addr string
107         var state *govpn.Handshake
108         var peerState *PeerState
109         var peer *govpn.Peer
110         var exists bool
111         states := make(map[string]*govpn.Handshake)
112         peers := make(map[string]*PeerState)
113         peerReadySink := make(chan PeerReadyEvent)
114         knownPeers := govpn.KnownPeers(make(map[string]**govpn.Peer))
115         var peerReady PeerReadyEvent
116         var udpPkt *govpn.UDPPkt
117         var udpPktData []byte
118         var ethEvent EthEvent
119         var peerId *govpn.PeerId
120         var handshakeProcessForce bool
121         ethSink := make(chan EthEvent)
122
123         log.Println(govpn.VersionGet())
124         if *stats != "" {
125                 log.Println("Stats are going to listen on", *stats)
126                 statsPort, err := net.Listen("tcp", *stats)
127                 if err != nil {
128                         panic(err)
129                 }
130                 go govpn.StatsProcessor(statsPort, &knownPeers)
131         }
132         log.Println("Server started")
133
134 MainCycle:
135         for {
136                 select {
137                 case <-termSignal:
138                         break MainCycle
139                 case <-hsHeartbeat:
140                         now := time.Now()
141                         for addr, hs := range states {
142                                 if hs.LastPing.Add(timeout).Before(now) {
143                                         log.Println("Deleting handshake state", addr)
144                                         hs.Zero()
145                                         delete(states, addr)
146                                 }
147                         }
148                         for addr, state := range peers {
149                                 if state.peer.LastPing.Add(timeout).Before(now) {
150                                         log.Println("Deleting peer", state.peer)
151                                         delete(peers, addr)
152                                         delete(knownPeers, addr)
153                                         downPath := path.Join(
154                                                 govpn.PeersPath,
155                                                 state.peer.Id.String(),
156                                                 "down.sh",
157                                         )
158                                         go govpn.ScriptCall(downPath, state.tap.Name)
159                                         state.terminate <- struct{}{}
160                                         state.peer.Zero()
161                                 }
162                         }
163                 case peerReady = <-peerReadySink:
164                         for addr, state := range peers {
165                                 if state.tap.Name != peerReady.iface {
166                                         continue
167                                 }
168                                 delete(peers, addr)
169                                 delete(knownPeers, addr)
170                                 state.terminate <- struct{}{}
171                                 state.peer.Zero()
172                                 break
173                         }
174                         addr = peerReady.peer.Addr.String()
175                         state := NewPeerState(peerReady.peer, peerReady.iface)
176                         if state == nil {
177                                 continue
178                         }
179                         peers[addr] = state
180                         knownPeers[addr] = &peerReady.peer
181                         states[addr].Zero()
182                         delete(states, addr)
183                         log.Println("Registered interface", peerReady.iface, "with peer", peer)
184                         go func(state *PeerState) {
185                                 for data := range state.sink {
186                                         ethSink <- EthEvent{
187                                                 peer:  state.peer,
188                                                 data:  data,
189                                                 ready: state.ready,
190                                         }
191                                 }
192                         }(state)
193                 case ethEvent = <-ethSink:
194                         if s, exists := peers[ethEvent.peer.Addr.String()]; !exists || s.peer != ethEvent.peer {
195                                 continue
196                         }
197                         ethEvent.peer.EthProcess(ethEvent.data, conn, ethEvent.ready)
198                 case udpPkt = <-udpSink:
199                         if udpPkt == nil {
200                                 udpReady <- struct{}{}
201                                 continue
202                         }
203                         udpPktData = udpBuf[:udpPkt.Size]
204                         addr = udpPkt.Addr.String()
205                         handshakeProcessForce = false
206                 HandshakeProcess:
207                         if _, exists = peers[addr]; handshakeProcessForce || !exists {
208                                 peerId = govpn.IDsCache.Find(udpPktData)
209                                 if peerId == nil {
210                                         log.Println("Unknown identity from", addr)
211                                         udpReady <- struct{}{}
212                                         continue
213                                 }
214                                 state, exists = states[addr]
215                                 if !exists {
216                                         state = govpn.HandshakeNew(udpPkt.Addr)
217                                         states[addr] = state
218                                 }
219                                 peer = state.Server(peerId, conn, udpPktData)
220                                 if peer != nil {
221                                         log.Println("Peer handshake finished", peer)
222                                         if _, exists = peers[addr]; exists {
223                                                 go func() {
224                                                         peerReadySink <- PeerReadyEvent{peer, peers[addr].tap.Name}
225                                                 }()
226                                         } else {
227                                                 go func() {
228                                                         upPath := path.Join(govpn.PeersPath, peer.Id.String(), "up.sh")
229                                                         result, err := govpn.ScriptCall(upPath, "")
230                                                         if err != nil {
231                                                                 return
232                                                         }
233                                                         sepIndex := bytes.Index(result, []byte{'\n'})
234                                                         if sepIndex < 0 {
235                                                                 sepIndex = len(result)
236                                                         }
237                                                         ifaceName := string(result[:sepIndex])
238                                                         peerReadySink <- PeerReadyEvent{peer, ifaceName}
239                                                 }()
240                                         }
241                                 }
242                                 if !handshakeProcessForce {
243                                         udpReady <- struct{}{}
244                                 }
245                                 continue
246                         }
247                         peerState, exists = peers[addr]
248                         if !exists {
249                                 udpReady <- struct{}{}
250                                 continue
251                         }
252                         // If it fails during processing, then try to work with it
253                         // as with handshake packet
254                         if !peerState.peer.UDPProcess(udpPktData, peerState.tap, udpReady) {
255                                 handshakeProcessForce = true
256                                 goto HandshakeProcess
257                         }
258                 }
259         }
260 }