8 #include <trust_router/tr_name.h>
9 #include <trp_internal.h>
10 #include <trp_rtable.h>
14 static int trps_destructor(void *object)
16 TRPS_INSTANCE *trps=talloc_get_type_abort(object, TRPS_INSTANCE);
17 if (trps->rtable!=NULL)
18 trp_rtable_free(trps->rtable);
22 TRPS_INSTANCE *trps_new (TALLOC_CTX *mem_ctx)
24 TRPS_INSTANCE *trps=talloc(mem_ctx, TRPS_INSTANCE);
31 trps->mq=tr_mq_new(trps);
33 /* failed to allocate mq */
37 trps->rtable=trp_rtable_new();
38 if (trps->rtable==NULL) {
39 /* failed to allocate rtable */
43 talloc_set_destructor((void *)trps, trps_destructor);
49 void trps_free (TRPS_INSTANCE *trps)
55 TR_MQ_MSG *trps_mq_pop(TRPS_INSTANCE *trps)
57 return tr_mq_pop(trps->mq);
60 void trps_mq_append(TRPS_INSTANCE *trps, TR_MQ_MSG *msg)
62 tr_mq_append(trps->mq, msg);
65 /* stand-in for a function that finds the connection for a particular peer */
67 static TRP_CONNECTION *trps_find_connection(TRPS_INSTANCE *trps)
73 void trps_add_connection(TRPS_INSTANCE *trps, TRP_CONNECTION *new)
78 trp_connection_append(trps->conn, new);
80 talloc_steal(trps, new);
83 /* ok to call more than once; guarantees connection no longer in the list.
84 * Caller is responsible for freeing the removed element afterwards. */
85 void trps_remove_connection(TRPS_INSTANCE *trps, TRP_CONNECTION *remove)
87 trps->conn=trp_connection_remove(trps->conn, remove);
90 void trps_add_trpc(TRPS_INSTANCE *trps, TRPC_INSTANCE *trpc)
95 trpc_append(trps->trpc, trpc);
97 talloc_steal(trps, trpc);
100 /* ok to call more than once; guarantees trpc no longer in the list.
101 * Caller is responsible for freeing the removed element afterwards. */
102 void trps_remove_trpc(TRPS_INSTANCE *trps, TRPC_INSTANCE *remove)
104 trps->trpc=trpc_remove(trps->trpc, remove);
107 TRP_RC trps_send_msg (TRPS_INSTANCE *trps, void *peer, const char *msg)
109 TALLOC_CTX *tmp_ctx=talloc_new(NULL);
110 TR_MQ_MSG *mq_msg=NULL;
114 /* Currently ignore peer and just send to an open connection.
115 * In reality, need to identify the correct peer and send via that
117 if (trps->trpc != NULL) {
118 if (trpc_get_status(trps->trpc)!=TRP_CONNECTION_UP)
119 tr_debug("trps_send_msg: skipping message sent while TRPC connection not up.");
121 mq_msg=tr_mq_msg_new(tmp_ctx, "trpc_send");
122 msg_dup=talloc_strdup(mq_msg, msg); /* get local copy in mq_msg context */
123 tr_mq_msg_set_payload(mq_msg, msg_dup, NULL); /* no need for a free() func */
124 trpc_mq_append(trps->trpc, mq_msg);
128 talloc_free(tmp_ctx);
132 static int trps_listen (TRPS_INSTANCE *trps, int port)
139 struct sockaddr_storage storage;
140 struct sockaddr_in in4;
143 struct sockaddr_in *saddr = (struct sockaddr_in *) &addr.in4;
145 saddr->sin_port = htons (port);
146 saddr->sin_family = AF_INET;
147 saddr->sin_addr.s_addr = INADDR_ANY;
149 if (0 > (conn = socket (AF_INET, SOCK_STREAM, 0)))
152 setsockopt(conn, SOL_SOCKET, SO_REUSEADDR, &optval, sizeof(optval));
154 if (0 > (rc = bind (conn, (struct sockaddr *) saddr, sizeof(struct sockaddr_in))))
157 if (0 > (rc = listen(conn, 512)))
160 tr_debug("trps_listen: TRP Server listening on port %d", port);
164 #if 0 /* remove this if I forget to do so */
165 /* returns EACCES if authorization is denied */
166 int trps_auth_cb(gss_name_t clientName, gss_buffer_t displayName, void *data)
168 TRPS_INSTANCE *trps = (TRPS_INSTANCE *)data;
171 if (0!=trps->auth_handler(clientName, displayName, trps->cookie)) {
172 tr_debug("trps_auth_cb: client '%.*s' denied authorization.", displayName->length, displayName->value);
173 result=EACCES; /* denied */
180 /* get the currently selected route if available */
181 TRP_RENTRY *trps_get_route(TRPS_INSTANCE *trps, TR_NAME *comm, TR_NAME *realm, TR_NAME *peer)
183 return trp_rtable_get_entry(trps->rtable, comm, realm, peer);
186 TRP_RENTRY *trps_get_selected_route(TRPS_INSTANCE *trps, TR_NAME *comm, TR_NAME *realm)
188 return trp_rtable_get_selected_entry(trps->rtable, comm, realm);
191 /* copy the result if you want to keep it */
192 TR_NAME *trps_get_next_hop(TRPS_INSTANCE *trps, TR_NAME *comm, TR_NAME *realm)
194 TRP_RENTRY *route=trps_get_selected_route(trps, comm, realm);
198 return trp_rentry_get_next_hop(route);
202 /* mark a route as retracted */
203 static void trps_retract_route(TRPS_INSTANCE *trps, TRP_RENTRY *entry)
205 trp_rentry_set_metric(entry, TRP_METRIC_INFINITY);
208 /* is this route retracted? */
209 static int trps_route_retracted(TRPS_INSTANCE *trps, TRP_RENTRY *entry)
211 return (trp_rentry_get_metric(entry)==TRP_METRIC_INFINITY);
214 static TRP_RC trps_read_message(TRPS_INSTANCE *trps, TRP_CONNECTION *conn, TR_MSG **msg)
221 tr_debug("trps_read_message: started");
222 if (err = gsscon_read_encrypted_token(trp_connection_get_fd(conn),
223 *(trp_connection_get_gssctx(conn)),
226 tr_debug("trps_read_message: error");
232 tr_debug("trps_read_message(): Request Received, %u bytes.", (unsigned) buflen);
233 tr_debug("trps_read_message(): %.*s", buflen, buf);
235 *msg=tr_msg_decode(buf, buflen);
240 peer=trp_connection_get_peer(conn);
241 /* verify we received a message we support, otherwise drop it now */
242 switch (tr_msg_get_msg_type(*msg)) {
244 trp_upd_set_peer(tr_msg_get_trp_upd(*msg), tr_dup_name(peer));
248 trp_req_set_peer(tr_msg_get_trp_req(*msg), tr_dup_name(peer));
252 tr_debug("trps_read_message: received unsupported message from %.*s", peer->len, peer->buf);
253 tr_msg_free_decoded(*msg);
255 return TRP_UNSUPPORTED;
261 int trps_get_listener(TRPS_INSTANCE *trps,
262 TRPS_MSG_FUNC msg_handler,
263 TRP_AUTH_FUNC auth_handler,
264 const char *hostname,
270 if (0 > (listen = trps_listen(trps, port))) {
272 if (0 == strerror_r(errno, errbuf, 256)) {
273 tr_debug("trps_get_listener: Error opening port %d: %s.", port, errbuf);
275 tr_debug("trps_get_listener: Unknown error openining port %d.", port);
280 /* opening port succeeded */
281 tr_debug("trps_get_listener: Opened port %d.", port);
283 /* make this socket non-blocking */
284 if (0 != fcntl(listen, F_SETFL, O_NONBLOCK)) {
285 tr_debug("trps_get_listener: Error setting O_NONBLOCK.");
292 /* store the caller's request handler & cookie */
293 trps->msg_handler = msg_handler;
294 trps->auth_handler = auth_handler;
295 trps->hostname = talloc_strdup(trps, hostname);
297 trps->cookie = cookie;
303 void trps_handle_connection(TRPS_INSTANCE *trps, TRP_CONNECTION *conn)
305 TALLOC_CTX *tmp_ctx=talloc_new(NULL);
309 /* try to establish a GSS context */
310 if (0!=trp_connection_auth(conn, trps->auth_handler, trps->cookie)) {
311 tr_notice("tr_trps_conn_thread: failed to authorize connection");
314 tr_notice("trps_handle_connection: authorized connection");
316 /* loop as long as the connection exists */
317 while (trp_connection_get_status(conn)==TRP_CONNECTION_UP) {
318 rc=trps_read_message(trps, conn, &msg);
321 trps->msg_handler(trps, conn, msg); /* send the TR_MSG off to the callback */
325 trp_connection_close(conn);
329 tr_debug("trps_handle_connection: trps_read_message failed (%d)", rc);
333 tr_debug("trps_handle_connection: connection closed.");
334 talloc_free(tmp_ctx);
337 static TRP_RC trps_validate_update(TRPS_INSTANCE *trps, TRP_UPD *upd)
339 if (trp_upd_get_inforec(upd)==NULL) {
340 tr_notice("trps_validate_update: received TRP update with no info records.");
344 if (trp_upd_get_peer(upd)==NULL) {
345 tr_notice("trps_validate_update: received TRP update without origin peer information.");
352 /* ensure that the update could be accepted if feasible */
353 static TRP_RC trps_validate_inforec(TRPS_INSTANCE *trps, TRP_INFOREC *rec)
355 switch(trp_inforec_get_type(rec)) {
356 case TRP_INFOREC_TYPE_ROUTE:
357 if ((trp_inforec_get_comm(rec)==NULL)
358 || (trp_inforec_get_realm(rec)==NULL)
359 || (trp_inforec_get_trust_router(rec)==NULL)
360 || (trp_inforec_get_next_hop(rec)==NULL)) {
361 tr_debug("trps_validate_inforec: missing record info.");
365 /* check for valid metric */
366 if ((trp_inforec_get_metric(rec)==TRP_METRIC_INVALID)
367 || (trp_inforec_get_metric(rec)>TRP_METRIC_INFINITY)) {
368 tr_debug("trps_validate_inforec: invalid metric.");
372 /* check for valid interval */
373 if (trp_inforec_get_interval(rec)==TRP_INTERVAL_INVALID) {
374 tr_debug("trps_validate_inforec: invalid interval.");
380 tr_notice("trps_validate_inforec: unsupported record type.");
381 return TRP_UNSUPPORTED;
387 /* link cost to a peer */
388 static unsigned int trps_cost(TRPS_INSTANCE *trps, TR_NAME *peer)
393 static unsigned int trps_advertised_metric(TRPS_INSTANCE *trps, TR_NAME *comm, TR_NAME *realm, TR_NAME *peer)
395 TRP_RENTRY *entry=trp_rtable_get_entry(trps->rtable, comm, realm, peer);
397 return TRP_METRIC_INFINITY;
398 return trp_rentry_get_metric(entry) + trps_cost(trps, peer);
401 static int trps_check_feasibility(TRPS_INSTANCE *trps, TRP_INFOREC *rec)
403 unsigned int rec_metric=trp_inforec_get_metric(rec);
404 unsigned int new_metric=0;
405 unsigned int current_metric=0;
406 TR_NAME *next_hop=NULL;
408 /* we check these in the validation stage, but just in case... */
409 if ((rec_metric==TRP_METRIC_INVALID) || (rec_metric>TRP_METRIC_INFINITY))
412 /* retractions (aka infinite metrics) are always feasible */
413 if (rec_metric==TRP_METRIC_INFINITY)
416 /* updates from our current next hop are always feasible*/
417 next_hop=trps_get_next_hop(trps,
418 trp_inforec_get_comm(rec),
419 trp_inforec_get_realm(rec));;
421 && (0==tr_name_cmp(next_hop,trp_inforec_get_next_hop(rec)))) {
426 /* compare the existing metric we advertise to what we would advertise
427 * if we accept this update */
428 current_metric=trps_advertised_metric(trps,
429 trp_inforec_get_comm(rec),
430 trp_inforec_get_realm(rec),
431 trp_inforec_get_next_hop(rec));
432 new_metric=rec_metric + trps_cost(trps, trp_inforec_get_next_hop(rec));
433 if (new_metric <= current_metric)
439 /* uses memory pointed to by *ts, also returns that value. On error, its contents are {0,0} */
440 static struct timespec *trps_compute_expiry(TRPS_INSTANCE *trps, unsigned int interval, struct timespec *ts)
442 const unsigned int small_factor=3; /* how many intervals we wait before expiring */
443 if (0!=clock_gettime(CLOCK_REALTIME, ts)) {
444 tr_err("trps_compute_expiry: could not read realtime clock.");
448 ts->tv_sec += small_factor*interval;
452 static TRP_RC trps_accept_update(TRPS_INSTANCE *trps, TRP_INFOREC *rec)
454 TRP_RENTRY *entry=NULL;
456 entry=trp_rtable_get_entry(trps->rtable,
457 trp_inforec_get_comm(rec),
458 trp_inforec_get_realm(rec),
459 trp_inforec_get_next_hop(rec));
461 entry=trp_rentry_new(NULL);
463 tr_err("trps_accept_update: unable to allocate new entry.");
467 trp_rentry_set_apc(entry, tr_dup_name(trp_inforec_get_comm(rec)));
468 trp_rentry_set_realm(entry, tr_dup_name(trp_inforec_get_realm(rec)));
469 trp_rentry_set_peer(entry, tr_dup_name(trp_inforec_get_next_hop(rec)));
470 trp_rentry_set_trust_router(entry, tr_dup_name(trp_inforec_get_trust_router(rec)));
471 trp_rentry_set_next_hop(entry, tr_dup_name(trp_inforec_get_next_hop(rec)));
472 if ((trp_rentry_get_apc(entry)==NULL)
473 ||(trp_rentry_get_realm(entry)==NULL)
474 ||(trp_rentry_get_peer(entry)==NULL)
475 ||(trp_rentry_get_trust_router(entry)==NULL)
476 ||(trp_rentry_get_next_hop(entry)==NULL)) {
477 /* at least one field could not be allocated */
478 tr_err("trps_accept_update: unable to allocate all fields for entry.");
479 trp_rentry_free(entry);
482 trp_rtable_add(trps->rtable, entry);
485 /* We now have an entry in the table, whether it's new or not. Update metric and expiry, unless
486 * the metric is infinity. An infinite metric can only occur here if we just retracted an existing
487 * route (we never accept retractions as new routes), so there is no risk of leaving the expiry
488 * time unset on a new route entry. */
489 tr_debug("trps_accept_update: accepting route update.");
490 trp_rentry_set_metric(entry, trp_inforec_get_metric(rec));
491 if (!trps_route_retracted(trps, entry)) {
492 tr_debug("trps_accept_update: route not retracted, setting expiry timer.");
493 trp_rentry_set_expiry(entry, trps_compute_expiry(trps,
494 trp_inforec_get_interval(rec),
495 trp_rentry_get_expiry(entry)));
500 /* TODO: handle community updates */
501 static TRP_RC trps_handle_update(TRPS_INSTANCE *trps, TRP_UPD *upd)
504 TRP_INFOREC *rec=NULL;
505 TRP_RENTRY *route=NULL;
507 if (trps_validate_update(trps, upd) != TRP_SUCCESS) {
508 tr_notice("trps_handle_update: received invalid TRP update.");
512 rec=trp_upd_get_inforec(upd);
513 for (;rec!=NULL; rec=trp_inforec_get_next(rec)) {
514 /* validate/sanity check the record update */
515 if (trps_validate_inforec(trps, rec) != TRP_SUCCESS) {
516 tr_notice("trps_handle_update: invalid record in TRP update.");
520 /* determine feasibility */
521 feas=trps_check_feasibility(trps, rec);
522 tr_debug("trps_handle_update: record feasibility=%d", feas);
524 /* do we have an existing route? */
525 route=trps_get_route(trps, trp_inforec_get_comm(rec), trp_inforec_get_realm(rec), trp_inforec_get_next_hop(rec));
527 /* there was a route table entry already */
528 tr_debug("trps_handle_updates: route entry already exists.");
530 /* Update is feasible. Accept it. */
531 trps_accept_update(trps, rec);
533 /* Update is infeasible. Ignore it unless the trust router has changed. */
534 if (0!=tr_name_cmp(trp_rentry_get_trust_router(route),
535 trp_inforec_get_trust_router(rec))) {
536 /* the trust router associated with the route has changed, treat update as a retraction */
537 trps_retract_route(trps, route);
541 /* No existing route table entry. Ignore it unless it is feasible and not a retraction. */
542 tr_debug("trps_handle_update: no route entry exists yet.");
543 if (feas && (trp_inforec_get_metric(rec) != TRP_METRIC_INFINITY))
544 trps_accept_update(trps, rec);
550 /* TODO: think this through more carefully. At least ought to add hysteresis
551 * to avoid flapping between routers or routes. */
552 static TRP_RC trps_update_active_routes(TRPS_INSTANCE *trps)
554 size_t n_apc=0, ii=0;
555 TR_NAME **apc=trp_rtable_get_apcs(trps->rtable, &n_apc);
556 size_t n_realm=0, jj=0;
557 TR_NAME **realm=NULL;
558 size_t n_entry=0, kk=0, kk_min=0;
559 TRP_RENTRY **entry=NULL, *cur_route=NULL;
560 unsigned int min_metric=0, cur_metric=0;
562 for (ii=0; ii<n_apc; ii++) {
563 realm=trp_rtable_get_apc_realms(trps->rtable, apc[ii], &n_realm);
564 for (jj=0; jj<n_realm; jj++) {
565 entry=trp_rtable_get_realm_entries(trps->rtable, apc[ii], realm[jj], &n_entry);
566 for (kk=0,min_metric=TRP_METRIC_INFINITY; kk<n_entry; kk++) {
567 if (trp_rentry_get_metric(entry[kk]) < min_metric) {
569 min_metric=trp_rentry_get_metric(entry[kk]);
573 cur_route=trps_get_selected_route(trps, apc[ii], realm[jj]);
574 if (cur_route!=NULL) {
575 cur_metric=trp_rentry_get_metric(cur_route);
576 if (min_metric < cur_metric) {
577 trp_rentry_set_selected(cur_route, 0);
578 trp_rentry_set_selected(entry[kk_min], 1);
579 } else if (cur_metric==TRP_METRIC_INFINITY)
580 trp_rentry_set_selected(cur_route, 0);
581 } else if (min_metric<TRP_METRIC_INFINITY)
582 trp_rentry_set_selected(entry[kk_min], 1);
585 entry=NULL; n_entry=0;
588 realm=NULL; n_realm=0;
596 TRP_RC trps_handle_tr_msg(TRPS_INSTANCE *trps, TR_MSG *tr_msg)
600 switch (tr_msg_get_msg_type(tr_msg)) {
602 rc=trps_handle_update(trps, tr_msg_get_trp_upd(tr_msg));
603 if (rc==TRP_SUCCESS) {
604 rc=trps_update_active_routes(trps);
609 return TRP_UNSUPPORTED;
612 /* unknown error or one we don't care about (e.g., TID messages) */