- changed config load strategy:
[strongswan.git] / src / stroke / stroke.c
1 /* Stroke for charon is the counterpart to whack from pluto
2 * Copyright (C) 2006 Martin Willi - Hochschule fuer Technik Rapperswil
3 *
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms of the GNU General Public License as published by the
6 * Free Software Foundation; either version 2 of the License, or (at your
7 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
8 *
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
11 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12 * for more details.
13 */
14
15 #include <stdlib.h>
16 #include <sys/types.h>
17 #include <sys/stat.h>
18 #include <sys/socket.h>
19 #include <sys/un.h>
20 #include <sys/fcntl.h>
21 #include <unistd.h>
22 #include <dirent.h>
23 #include <errno.h>
24 #include <stdio.h>
25 #include <linux/stddef.h>
26
27 #include "stroke.h"
28
29 #define streq(a, b) (strcmp((a), (b)) == 0) /* clearer shorthand */
30
31 static char* push_string(stroke_msg_t **strm, char *string)
32 {
33 stroke_msg_t *stroke_msg;
34 size_t string_length;
35
36 if (string == NULL)
37 {
38 return NULL;
39 }
40 stroke_msg = *strm;
41 string_length = strlen(string) + 1;
42 stroke_msg->length += string_length;
43
44 stroke_msg = realloc(stroke_msg, stroke_msg->length);
45 strcpy((char*)stroke_msg + stroke_msg->length - string_length, string);
46
47 *strm = stroke_msg;
48 return (char*)(u_int)stroke_msg->length - string_length;
49 }
50
51 static int send_stroke_msg (stroke_msg_t *msg)
52 {
53 struct sockaddr_un ctl_addr = { AF_UNIX, STROKE_SOCKET };
54 int sock;
55 char buffer[64];
56 int byte_count;
57
58 sock = socket(AF_UNIX, SOCK_STREAM, 0);
59 if (sock < 0)
60 {
61 fprintf(stderr, "Opening unix socket %s: %s\n", STROKE_SOCKET, strerror(errno));
62 return -1;
63 }
64 if (connect(sock, (struct sockaddr *)&ctl_addr,
65 offsetof(struct sockaddr_un, sun_path) + strlen(ctl_addr.sun_path)) < 0)
66 {
67 fprintf(stderr, "Connect to socket failed: %s\n", strerror(errno));
68 close(sock);
69 return -1;
70 }
71
72 /* send message */
73 if (write(sock, msg, msg->length) != msg->length)
74 {
75 fprintf(stderr, "writing to socket failed: %s\n", strerror(errno));
76 close(sock);
77 return -1;
78 }
79
80 while ((byte_count = read(sock, buffer, sizeof(buffer)-1)) > 0)
81 {
82 buffer[byte_count] = '\0';
83 printf("%s", buffer);
84 }
85 if (byte_count < 0)
86 {
87 fprintf(stderr, "reading from socket failed: %s\n", strerror(errno));
88 }
89
90 close(sock);
91 return 0;
92 }
93
94 static int add_connection(char *name,
95 char *my_id, char *other_id,
96 char *my_addr, char *other_addr,
97 char *my_net, char *other_net,
98 u_int my_netmask, u_int other_netmask)
99 {
100 stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
101 int res;
102
103 msg->length = sizeof(stroke_msg_t);
104 msg->type = STR_ADD_CONN;
105
106 msg->add_conn.name = push_string(&msg, name);
107 msg->add_conn.ikev2 = 1;
108
109 msg->add_conn.me.id = push_string(&msg, my_id);
110 msg->add_conn.me.address = push_string(&msg, my_addr);
111 msg->add_conn.me.subnet = push_string(&msg, my_net);
112 msg->add_conn.me.subnet_mask = my_netmask;
113 msg->add_conn.me.cert = NULL;
114
115 msg->add_conn.other.id = push_string(&msg, other_id);
116 msg->add_conn.other.address = push_string(&msg, other_addr);
117 msg->add_conn.other.subnet = push_string(&msg, other_net);
118 msg->add_conn.other.subnet_mask = other_netmask;
119 msg->add_conn.other.cert = NULL;
120
121 res = send_stroke_msg(msg);
122 free(msg);
123 return res;
124 }
125
126 static int initiate_connection(char *name)
127 {
128 stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
129 int res;
130
131 msg->length = sizeof(stroke_msg_t);
132 msg->type = STR_INITIATE;
133 msg->initiate.name = push_string(&msg, name);
134 res = send_stroke_msg(msg);
135 free(msg);
136 return res;
137 }
138
139 static int terminate_connection(char *name)
140 {
141 stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
142 int res;
143
144 msg->length = sizeof(stroke_msg_t);
145 msg->type = STR_TERMINATE;
146 msg->initiate.name = push_string(&msg, name);
147 res = send_stroke_msg(msg);
148 free(msg);
149 return res;
150 }
151
152 static int show_status(char *mode, char *connection)
153 {
154 stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
155 int res;
156
157 msg->length = sizeof(stroke_msg_t);
158 if (strcmp(mode, "statusall") == 0)
159 {
160 msg->type = STR_STATUS_ALL;
161 }
162 else
163 {
164 msg->type = STR_STATUS;
165 }
166 msg->status.name = push_string(&msg, connection);
167 res = send_stroke_msg(msg);
168 free(msg);
169 return res;
170 }
171
172 static int list_certs(void)
173 {
174 stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
175 int res;
176
177 msg->length = sizeof(stroke_msg_t);
178 msg->type = STR_LIST_CERTS;
179 res = send_stroke_msg(msg);
180 free(msg);
181 return res;
182 }
183
184 static int set_logtype(char *context, char *type, int enable)
185 {
186 stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
187 int res;
188
189 msg->length = sizeof(stroke_msg_t);
190 msg->type = STR_LOGTYPE;
191 msg->logtype.context = push_string(&msg, context);
192 msg->logtype.type = push_string(&msg, type);
193 msg->logtype.enable = enable;
194 res = send_stroke_msg(msg);
195 free(msg);
196 return res;
197 }
198
199 static int set_loglevel(char *context, u_int level)
200 {
201 stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
202 int res;
203
204 msg->length = sizeof(stroke_msg_t);
205 msg->type = STR_LOGLEVEL;
206 msg->loglevel.context = push_string(&msg, context);
207 msg->loglevel.level = level;
208 res = send_stroke_msg(msg);
209 free(msg);
210 return res;
211 }
212
213 static void exit_error(char *error)
214 {
215 if (error)
216 {
217 fprintf(stderr, "%s\n", error);
218 }
219 exit(-1);
220 }
221
222 static void exit_usage(char *error)
223 {
224 printf("Usage:\n");
225 printf(" Add a connection:\n");
226 printf(" stroke add NAME MY_ID OTHER_ID MY_ADDR OTHER_ADDR\\\n");
227 printf(" MY_NET OTHER_NET MY_NETBITS OTHER_NETBITS\n");
228 printf(" where: ID is any IKEv2 ID \n");
229 printf(" ADDR is a IPv4 address\n");
230 printf(" NET is a IPv4 address of the subnet to tunnel\n");
231 printf(" NETBITS is the size of the subnet, as the \"24\" in 192.168.0.0/24\n");
232 printf(" Initiate a connection:\n");
233 printf(" stroke up NAME\n");
234 printf(" where: NAME is a connection name added with \"stroke add\"\n");
235 printf(" Terminate a connection:\n");
236 printf(" stroke down NAME\n");
237 printf(" where: NAME is a connection name added with \"stroke add\"\n");
238 printf(" Set logtype for a logging context:\n");
239 printf(" stroke logtype CONTEXT TYPE ENABLE\n");
240 printf(" where: CONTEXT is PARSR|GNRAT|IKESA|SAMGR|CHDSA|MESSG|TPOOL|WORKR|SCHED|\n");
241 printf(" SENDR|RECVR|SOCKT|TESTR|DAEMN|CONFG|ENCPL|PAYLD\n");
242 printf(" TYPE is CONTROL|ERROR|AUDIT|RAW|PRIVATE\n");
243 printf(" ENABLE is 0|1\n");
244 printf(" Set loglevel for a logging context:\n");
245 printf(" stroke loglevel CONTEXT LEVEL\n");
246 printf(" where: CONTEXT is PARSR|GNRAT|IKESA|SAMGR|CHDSA|MESSG|TPOOL|WORKR|SCHED|\n");
247 printf(" SENDR|RECVR|SOCKT|TESTR|DAEMN|CONFG|ENCPL|PAYLD\n");
248 printf(" LEVEL is 0|1|2|3\n");
249 printf(" Show connection status:\n");
250 printf(" stroke status\n");
251 printf(" Show list of locally loaded certificates:\n");
252 printf(" stroke listcerts\n");
253 exit_error(error);
254 }
255
256 int main(int argc, char *argv[])
257 {
258 int res = 0;
259 char *op;
260
261 if (argc < 2)
262 {
263 exit_usage(NULL);
264 }
265
266 op = argv[1];
267
268 if (streq(op, "status") || streq(op, "statusall"))
269 {
270 res = show_status(op, argc > 2 ? argv[2] : NULL);
271 }
272 else if (streq(op, "listcerts") || streq(op, "listall"))
273 {
274 res = list_certs();
275 }
276 else if (streq(op, "up"))
277 {
278 if (argc < 3)
279 {
280 exit_usage("\"up\" needs a connection name");
281 }
282 res = initiate_connection(argv[2]);
283 }
284 else if (streq(op, "down"))
285 {
286 if (argc < 3)
287 {
288 exit_usage("\"down\" needs a connection name");
289 }
290 res = terminate_connection(argv[2]);
291 }
292 else if (streq(op, "add"))
293 {
294 if (argc < 11)
295 {
296 exit_usage("\"add\" needs more parameters...");
297 }
298 res = add_connection(argv[2],
299 argv[3], argv[4],
300 argv[5], argv[6],
301 argv[7], argv[8],
302 atoi(argv[9]), atoi(argv[10]));
303 }
304 else if (streq(op, "logtype"))
305 {
306 if (argc < 5)
307 {
308 exit_usage("\"logtype\" needs more parameters...");
309 }
310 res = set_logtype(argv[2], argv[3], atoi(argv[4]));
311 }
312 else if (streq(op, "loglevel"))
313 {
314 if (argc < 4)
315 {
316 exit_usage("\"logtype\" needs more parameters...");
317 }
318 res = set_loglevel(argv[2], atoi(argv[3]));
319 }
320 else
321 {
322 exit_usage(NULL);
323 }
324
325 return res;
326 }