config.c 33.2 KB
Newer Older
1
/* Copyright 2001,2002,2003 Roger Dingledine, Matej Pfajfar. */
2
3
4
/* See LICENSE for licensing information */
/* $Id$ */

Nick Mathewson's avatar
Nick Mathewson committed
5
6
7
8
9
10
11
/**
 * /file config.c
 *
 * /brief Code to parse and interpret configuration files.
 *
 **/

Roger Dingledine's avatar
Roger Dingledine committed
12
#include "or.h"
Roger Dingledine's avatar
Roger Dingledine committed
13

Nick Mathewson's avatar
Nick Mathewson committed
14
15
16
17
18
19
/** Enumeration of types which option values can take */
typedef enum config_type_t {
  CONFIG_TYPE_STRING = 0, /**< An arbitrary string. */
  CONFIG_TYPE_INT, /**< An integer */
  CONFIG_TYPE_DOUBLE, /**< A floating-point value */
  CONFIG_TYPE_BOOL, /**< A boolean value, expressed as 0 or 1. */
20
21
  CONFIG_TYPE_CSV, /**< A list of strings, separated by commas and optional
                    * whitespace. */
Nick Mathewson's avatar
Nick Mathewson committed
22
23
  CONFIG_TYPE_LINELIST, /**< Uninterpreted config lines */
} config_type_t;
24

Nick Mathewson's avatar
Nick Mathewson committed
25
/** Largest allowed config line */
26
#define CONFIG_LINE_T_MAXLEN 4096
27
28
29

static FILE *config_open(const unsigned char *filename);
static int config_close(FILE *f);
30
31
32
static struct config_line_t *config_get_commandlines(int argc, char **argv);
static struct config_line_t *config_get_lines(FILE *f);
static void config_free_lines(struct config_line_t *front);
33
static int config_compare(struct config_line_t *c, const char *key, config_type_t type, void *arg);
34
static int config_assign(or_options_t *options, struct config_line_t *list);
35

Nick Mathewson's avatar
Nick Mathewson committed
36
/** Open a configuration file for reading */
37
static FILE *config_open(const unsigned char *filename) {
Roger Dingledine's avatar
Roger Dingledine committed
38
  tor_assert(filename);
39
40
41
42
43
44
45
  if (strspn(filename,CONFIG_LEGAL_FILENAME_CHARACTERS) != strlen(filename)) {
    /* filename has illegal letters */
    return NULL;
  }
  return fopen(filename, "r");
}

Nick Mathewson's avatar
Nick Mathewson committed
46
/** Close the configuration file */
47
static int config_close(FILE *f) {
Roger Dingledine's avatar
Roger Dingledine committed
48
  tor_assert(f);
49
50
51
  return fclose(f);
}

Nick Mathewson's avatar
Nick Mathewson committed
52
/** Helper: Read a list of configuration options from the command line. */
53
54
55
static struct config_line_t *config_get_commandlines(int argc, char **argv) {
  struct config_line_t *new;
  struct config_line_t *front = NULL;
56
57
58
  char *s;
  int i = 1;

Roger Dingledine's avatar
Roger Dingledine committed
59
  while(i < argc-1) {
60
61
62
63
64
65
    if(!strcmp(argv[i],"-f")) {
//      log(LOG_DEBUG,"Commandline: skipping over -f.");
      i+=2; /* this is the config file option. ignore it. */
      continue;
    }

66
    new = tor_malloc(sizeof(struct config_line_t));
67
68
69
    s = argv[i];
    while(*s == '-')
      s++;
70
71
    new->key = tor_strdup(s);
    new->value = tor_strdup(argv[i+1]);
72
73
74
75
76
77
78
79
80
81

    log(LOG_DEBUG,"Commandline: parsed keyword '%s', value '%s'",
      new->key, new->value);
    new->next = front;
    front = new;
    i += 2;
  }
  return front;
}

Nick Mathewson's avatar
Nick Mathewson committed
82
83
/** Helper: allocate a new configuration option mapping 'key' to 'val',
 * prepend it to 'front', and return the newly allocated config_line_t */
84
85
86
87
88
89
90
91
92
93
94
95
96
static struct config_line_t *
config_line_prepend(struct config_line_t *front,
                    const char *key,
                    const char *val)
{
  struct config_line_t *newline;
  newline = tor_malloc(sizeof(struct config_line_t));
  newline->key = tor_strdup(key);
  newline->value = tor_strdup(val);
  newline->next = front;
  return newline;
}

97
/** Helper: parse the config file and strdup into key/value
Nick Mathewson's avatar
Nick Mathewson committed
98
99
 * strings. Return list, or NULL if parsing the file failed.  Warn and
 * ignore any misformatted lines. */
100
101
102
103
static struct config_line_t *config_get_lines(FILE *f) {

  struct config_line_t *front = NULL;
  char line[CONFIG_LINE_T_MAXLEN];
104
105
  int result;
  char *key, *value;
106

107
  while( (result=parse_line_from_file(line,sizeof(line),f,&key,&value)) > 0) {
108
    front = config_line_prepend(front, key, value);
Roger Dingledine's avatar
Roger Dingledine committed
109
  }
110
111
  if(result < 0)
    return NULL;
112
  return front;
Roger Dingledine's avatar
Roger Dingledine committed
113
114
}

Nick Mathewson's avatar
Nick Mathewson committed
115
116
117
/**
 * Free all the configuration lines on the linked list <b>front</b>.
 */
118
119
static void config_free_lines(struct config_line_t *front) {
  struct config_line_t *tmp;
120
121
122
123
124
125
126
127
128
129
130

  while(front) {
    tmp = front;
    front = tmp->next;

    free(tmp->key);
    free(tmp->value);
    free(tmp);
  }
}

131
132
/**
 * Given a list of comma-separated entries, each surrounded by optional
133
 * whitespace, insert copies of the entries (in order) into lst, without
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
 * their surrounding whitespace.
 */
static void parse_csv_into_smartlist(smartlist_t *lst, const char *val)
{
  const char *cp, *start, *end;

  cp = val;
  while (1) {
    while (isspace(*cp))
      ++cp;
    start = cp;
    end = strchr(cp, ',');
    if (!end)
      end = strchr(cp, '\0');
    for (cp=end-1; cp>=start && isspace(*cp); --cp)
      ;
    /* Now start points to the first nonspace character of an entry,
     * end points to the terminator of that entry,
     * and cp points to the last nonspace character of an entry. */
    tor_assert(start <= cp);
    tor_assert(cp <= end);
    tor_assert(*end == '\0' || *end == ',');
    tor_assert((!isspace(*start) && !isspace(*cp)) || start==cp);
    smartlist_add(lst, tor_strndup(start, cp-start));
    if (!*end)
      break;
    cp = end+1;
  }
}

Nick Mathewson's avatar
Nick Mathewson committed
164
165
166
167
168
/** Search the linked list <b>c</b> for any option whose key is <b>key</b>.
 * If such an option is found, interpret it as of type <b>type</b>, and store
 * the result in <b>arg</b>.  If the option is misformatted, log a warning and
 * skip it.
 */
169
static int config_compare(struct config_line_t *c, const char *key, config_type_t type, void *arg) {
170
  int i;
171
172
173
174

  if(strncasecmp(c->key,key,strlen(c->key)))
    return 0;

175
176
177
178
179
  if(strcasecmp(c->key,key)) {
    tor_free(c->key);
    c->key = tor_strdup(key);
  }

180
  /* it's a match. cast and assign. */
181
  log_fn(LOG_DEBUG,"Recognized keyword '%s' as %s, using value '%s'.",c->key,key,c->value);
182
183

  switch(type) {
Roger Dingledine's avatar
Roger Dingledine committed
184
    case CONFIG_TYPE_INT:
185
      *(int *)arg = atoi(c->value);
186
      break;
187
188
189
    case CONFIG_TYPE_BOOL:
      i = atoi(c->value);
      if (i != 0 && i != 1) {
Roger Dingledine's avatar
Roger Dingledine committed
190
        log(LOG_WARN, "Boolean keyword '%s' expects 0 or 1", c->key);
191
        return 0;
192
193
194
      }
      *(int *)arg = i;
      break;
195
    case CONFIG_TYPE_STRING:
196
      tor_free(*(char **)arg);
197
      *(char **)arg = tor_strdup(c->value);
198
      break;
199
200
    case CONFIG_TYPE_DOUBLE:
      *(double *)arg = atof(c->value);
201
      break;
202
203
204
205
206
207
208
209
    case CONFIG_TYPE_CSV:
      if (arg) {
        SMARTLIST_FOREACH((smartlist_t*)arg, char *, cp, tor_free(cp));
        smartlist_free((smartlist_t*)arg);
      }
      arg = smartlist_create();
      parse_csv_into_smartlist(arg, c->value);
      break;
210
211
212
213
214
215
216
    case CONFIG_TYPE_LINELIST:
      /* Note: this reverses the order that the lines appear in.  That's
       * just fine, since we build up the list of lines reversed in the
       * first place. */
      *(struct config_line_t**)arg =
        config_line_prepend(*(struct config_line_t**)arg, c->key, c->value);
      break;
217
218
219
220
  }
  return 1;
}

Nick Mathewson's avatar
Nick Mathewson committed
221
222
/** Iterate through the linked list of options <b>list</b>.
 * For each item, convert as appropriate and assign to <b>options</b>.
223
224
 * If an item is unrecognized, return -1 immediately,
 * else return 0 for success. */
225
static int config_assign(or_options_t *options, struct config_line_t *list) {
226
227
228
229
230
231
232

  while(list) {
    if(

    /* order matters here! abbreviated arguments use the first match. */

    /* string options */
233
    config_compare(list, "Address",        CONFIG_TYPE_STRING, &options->Address) ||
234
    config_compare(list, "AuthoritativeDirectory",CONFIG_TYPE_BOOL, &options->AuthoritativeDir) ||
235

236
237
238
    config_compare(list, "BandwidthRate",  CONFIG_TYPE_INT, &options->BandwidthRate) ||
    config_compare(list, "BandwidthBurst", CONFIG_TYPE_INT, &options->BandwidthBurst) ||

239
    config_compare(list, "ClientOnly",     CONFIG_TYPE_BOOL, &options->ClientOnly) ||
240
    config_compare(list, "ContactInfo",    CONFIG_TYPE_STRING, &options->ContactInfo) ||
241

242
    config_compare(list, "DebugLogFile",   CONFIG_TYPE_STRING, &options->DebugLogFile) ||
243
    config_compare(list, "DataDirectory",  CONFIG_TYPE_STRING, &options->DataDirectory) ||
244
    config_compare(list, "DirPort",        CONFIG_TYPE_INT, &options->DirPort) ||
245
    config_compare(list, "DirBindAddress", CONFIG_TYPE_LINELIST, &options->DirBindAddress) ||
246
247
    config_compare(list, "DirFetchPostPeriod",CONFIG_TYPE_INT, &options->DirFetchPostPeriod) ||

248
249
    config_compare(list, "ExitNodes",      CONFIG_TYPE_STRING, &options->ExitNodes) ||
    config_compare(list, "EntryNodes",     CONFIG_TYPE_STRING, &options->EntryNodes) ||
250
251
    config_compare(list, "StrictExitNodes", CONFIG_TYPE_BOOL, &options->StrictExitNodes) ||
    config_compare(list, "StrictEntryNodes", CONFIG_TYPE_BOOL, &options->StrictEntryNodes) ||
252
    config_compare(list, "ExitPolicy",     CONFIG_TYPE_LINELIST, &options->ExitPolicy) ||
253
    config_compare(list, "ExcludeNodes",   CONFIG_TYPE_STRING, &options->ExcludeNodes) ||
254

255
    config_compare(list, "FascistFirewall",CONFIG_TYPE_BOOL, &options->FascistFirewall) ||
256
    config_compare(list, "FirewallPorts",CONFIG_TYPE_CSV, &options->FirewallPorts) ||
257

258
    config_compare(list, "Group",          CONFIG_TYPE_STRING, &options->Group) ||
259

260
261
262
263
264
    config_compare(list, "HiddenServiceDir", CONFIG_TYPE_LINELIST, &options->RendConfigLines)||
    config_compare(list, "HiddenServicePort", CONFIG_TYPE_LINELIST, &options->RendConfigLines)||
    config_compare(list, "HiddenServiceNodes", CONFIG_TYPE_LINELIST, &options->RendConfigLines)||
    config_compare(list, "HiddenServiceExcludeNodes", CONFIG_TYPE_LINELIST, &options->RendConfigLines)||

265
266
267
268
    config_compare(list, "IgnoreVersion",  CONFIG_TYPE_BOOL, &options->IgnoreVersion) ||

    config_compare(list, "KeepalivePeriod",CONFIG_TYPE_INT, &options->KeepalivePeriod) ||

269
270
    config_compare(list, "LogLevel",       CONFIG_TYPE_LINELIST, &options->LogOptions) ||
    config_compare(list, "LogFile",        CONFIG_TYPE_LINELIST, &options->LogOptions) ||
271
272
273
    config_compare(list, "LinkPadding",    CONFIG_TYPE_BOOL, &options->LinkPadding) ||

    config_compare(list, "MaxConn",        CONFIG_TYPE_INT, &options->MaxConn) ||
274
    config_compare(list, "MaxOnionsPending",CONFIG_TYPE_INT, &options->MaxOnionsPending) ||
275
276

    config_compare(list, "Nickname",       CONFIG_TYPE_STRING, &options->Nickname) ||
277
    config_compare(list, "NewCircuitPeriod",CONFIG_TYPE_INT, &options->NewCircuitPeriod) ||
278
    config_compare(list, "NumCpus",        CONFIG_TYPE_INT, &options->NumCpus) ||
279

280
    config_compare(list, "ORPort",         CONFIG_TYPE_INT, &options->ORPort) ||
281
    config_compare(list, "ORBindAddress",  CONFIG_TYPE_LINELIST, &options->ORBindAddress) ||
282
    config_compare(list, "OutboundBindAddress",CONFIG_TYPE_STRING, &options->OutboundBindAddress) ||
283

284
    config_compare(list, "PidFile",        CONFIG_TYPE_STRING, &options->PidFile) ||
285
    config_compare(list, "PathlenCoinWeight",CONFIG_TYPE_DOUBLE, &options->PathlenCoinWeight) ||
286
287
288

    config_compare(list, "RouterFile",     CONFIG_TYPE_STRING, &options->RouterFile) ||
    config_compare(list, "RunAsDaemon",    CONFIG_TYPE_BOOL, &options->RunAsDaemon) ||
289
    config_compare(list, "RunTesting",     CONFIG_TYPE_BOOL, &options->RunTesting) ||
290
    config_compare(list, "RecommendedVersions",CONFIG_TYPE_STRING, &options->RecommendedVersions) ||
291
292
    config_compare(list, "RendNodes",      CONFIG_TYPE_STRING, &options->RendNodes) ||
    config_compare(list, "RendExcludeNodes",CONFIG_TYPE_STRING, &options->RendExcludeNodes) ||
293

294
    config_compare(list, "SocksPort",      CONFIG_TYPE_INT, &options->SocksPort) ||
295
296
    config_compare(list, "SocksBindAddress",CONFIG_TYPE_LINELIST,&options->SocksBindAddress) ||
    config_compare(list, "SocksPolicy",     CONFIG_TYPE_LINELIST,&options->SocksPolicy) ||
297
298
299

    config_compare(list, "TrafficShaping", CONFIG_TYPE_BOOL, &options->TrafficShaping) ||

300
301
302
    config_compare(list, "User",           CONFIG_TYPE_STRING, &options->User)


303
304
305
    ) {
      /* then we're ok. it matched something. */
    } else {
306
307
      log_fn(LOG_WARN,"Unknown keyword '%s'. Failing.",list->key);
      return -1;
308
309
310
    }

    list = list->next;
Roger Dingledine's avatar
Roger Dingledine committed
311
  }
312
  return 0;
313
314
}

315
const char default_dirservers_string[] =
316
317
318
319
"router moria1 18.244.0.188 9001 9021 9031\n"
"platform Tor 0.0.6rc1 on Linux moria.mit.edu i686\n"
"published 2004-04-25 21:54:28\n"
"bandwidth 800000 10000000\n"
320
321
322
323
324
325
326
327
328
329
330
331
"onion-key\n"
"-----BEGIN RSA PUBLIC KEY-----\n"
"MIGJAoGBANoIvHieyHUTzIacbnWOnyTyzGrLOdXqbcjz2GGMxyHEd5K1bO1ZBNHP\n"
"9i5qLQpN5viFk2K2rEGuG8tFgDEzSWZEtBqv3NVfUdiumdERWMBwlaQ0MVK4C+jf\n"
"y5gZ8KI3o9ZictgPS1AQF+Kk932/vIHTuRIUKb4ILTnQilNvID0NAgMBAAE=\n"
"-----END RSA PUBLIC KEY-----\n"
"signing-key\n"
"-----BEGIN RSA PUBLIC KEY-----\n"
"MIGJAoGBAMHa0ZC/jo2Q2DrwKYF/6ZbmZ27PFYG91u4gUzzmZ/VXLpZ8wNzEV3oW\n"
"nt+I61048fBiC1frT1/DZ351n2bLSk9zJbB6jyGZJn0380FPRX3+cXyXS0Gq8Ril\n"
"xkhMQf5XuNFUb8UmYPSOH4WErjvYjKvU+gfjbK/82Jo9SuHpYz+BAgMBAAE=\n"
"-----END RSA PUBLIC KEY-----\n"
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
"reject 0.0.0.0/255.0.0.0:*\n"
"reject 169.254.0.0/255.255.0.0:*\n"
"reject 127.0.0.0/255.0.0.0:*\n"
"reject 192.168.0.0/255.255.0.0:*\n"
"reject 10.0.0.0/255.0.0.0:*\n"
"reject 172.16.0.0/255.240.0.0:*\n"
"accept *:20-22\n"
"accept *:53\n"
"accept *:79-80\n"
"accept *:110\n"
"accept *:143\n"
"accept *:443\n"
"accept *:873\n"
"accept *:993\n"
"accept *:995\n"
"accept *:1024-65535\n"
"reject *:*\n"
349
350
"router-signature\n"
"-----BEGIN SIGNATURE-----\n"
351
352
353
"o1eAoRHDAEAXsnh5wN++vIwrupd+DbAJ2p3wxHDrmqxTpygzxxCnyQyhMfX03ua2\n"
"4iplyNlwyFwzWcw0sk31otlO2HBYXT1V9G0YxGtKMOeOBMHjfGbUjGvEALHzWi4z\n"
"8DXGJp13zgnUyP4ZA6xaGROwcT6oB5e7UlztvvpGxTg=\n"
354
355
"-----END SIGNATURE-----\n"
"\n"
356
357
358
359
"router moria2 18.244.0.188 9002 9022 9032\n"
"platform Tor 0.0.6rc1 on Linux moria.mit.edu i686\n"
"published 2004-04-25 21:54:30\n"
"bandwidth 800000 10000000\n"
360
361
362
363
364
365
366
367
368
369
370
371
"onion-key\n"
"-----BEGIN RSA PUBLIC KEY-----\n"
"MIGJAoGBAM4Cc/npgYC54XrYLC+grVxJp7PDmNO2DRRJOxKttBBtvLpnR1UaueTi\n"
"kyknT5kmlx+ihgZF/jmye//2dDUp2+kK/kSkpRV4xnDLXZmed+sNSQxqmm9TtZQ9\n"
"/hjpxhp5J9HmUTYhntBs+4E4CUKokmrI6oRLoln4SA39AX9QLPcnAgMBAAE=\n"
"-----END RSA PUBLIC KEY-----\n"
"signing-key\n"
"-----BEGIN RSA PUBLIC KEY-----\n"
"MIGJAoGBAOcrht/y5rkaahfX7sMe2qnpqoPibsjTSJaDvsUtaNP/Bq0MgNDGOR48\n"
"rtwfqTRff275Edkp/UYw3G3vSgKCJr76/bqOHCmkiZrnPV1zxNfrK18gNw2Cxre0\n"
"nTA+fD8JQqpPtb8b0SnG9kwy75eS//sRu7TErie2PzGMxrf9LH0LAgMBAAE=\n"
"-----END RSA PUBLIC KEY-----\n"
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
"reject 0.0.0.0/255.0.0.0:*\n"
"reject 169.254.0.0/255.255.0.0:*\n"
"reject 127.0.0.0/255.0.0.0:*\n"
"reject 192.168.0.0/255.255.0.0:*\n"
"reject 10.0.0.0/255.0.0.0:*\n"
"reject 172.16.0.0/255.240.0.0:*\n"
"accept *:20-22\n"
"accept *:53\n"
"accept *:79-80\n"
"accept *:110\n"
"accept *:143\n"
"accept *:443\n"
"accept *:873\n"
"accept *:993\n"
"accept *:995\n"
"accept *:1024-65535\n"
"reject *:*\n"
389
390
"router-signature\n"
"-----BEGIN SIGNATURE-----\n"
391
392
393
"RKROLwP1ExjTZeg6wuN0pzYqed9IJUd5lAe9hp4ritbnmJAgS6qfww6jgx61CfUR\n"
"6SElhOLE7Q77jAdoL45Ji5pn/Y+Q+E+5lJm1E/ed9ha+YsOPaOc7z6GQ7E4mihCL\n"
"gI1vsw92+P1Ty4RHj6fyD9DhbV19nh2Qs+pvGJOS2FY=\n"
394
395
"-----END SIGNATURE-----\n"
"\n"
396
397
398
399
"router tor26 62.116.124.106 9001 9050 9030\n"
"platform Tor 0.0.6 on Linux seppia i686\n"
"published 2004-05-06 21:33:23\n"
"bandwidth 500000 10000000\n"
400
401
"onion-key\n"
"-----BEGIN RSA PUBLIC KEY-----\n"
402
403
404
"MIGJAoGBAMEHdDnpj3ik1AF1xe/VqjoguH2DbANifYqXXfempu0fS+tU9FGo6dU/\n"
"fnVHAZwL9Ek9k2rMzumShi1RduK9p035R/Gk+PBBcLfvwYJ/Nat+ZO/L8jn/3bZe\n"
"ieQd9CKj2LjNGKpRNry37vkwMGIOIlegwK+2us8aXJ7sIvlNts0TAgMBAAE=\n"
405
406
407
"-----END RSA PUBLIC KEY-----\n"
"signing-key\n"
"-----BEGIN RSA PUBLIC KEY-----\n"
408
409
410
"MIGJAoGBAMQgV2gXLbXgesWgeAsj8P1Uvm/zibrFXqwDq27lLKNgWGYGX2ax3LyT\n"
"3nzI1Y5oLs4kPKTsMM5ft9aokwf417lKoCRlZc9ptfRbgxDx90c9GtWVmkrmDvCK\n"
"ae59TMoXIiGfZiwWT6KKq5Zm9/Fu2Il3B2vHGkKJYKixmiBJRKp/AgMBAAE=\n"
411
"-----END RSA PUBLIC KEY-----\n"
412
413
414
"accept 62.245.184.24:25\n"
"accept 62.116.124.106:6666-6670\n"
"accept *:48099\n"
415
"reject *:*\n"
416
417
"router-signature\n"
"-----BEGIN SIGNATURE-----\n"
418
419
420
"qh/xRoqfLNFzPaB8VdpbdMAwRyuk5qjx4LeLVQ2pDwTZ55PqmG99+VKUNte2WTTD\n"
"7dZEA7um2rueohGe4nYmvbhJWr20/I0ZxmWDRDvFy0b5nwzDMGvLvDw95Zu/XJQ2\n"
"md32NE3y9VZCfbCN+GlvETX3fdR3Svzcm8Kzesg2/s4=\n"
421
422
423
"-----END SIGNATURE-----\n"
;

424
int config_assign_default_dirservers(void) {
425
  if(router_load_routerlist_from_string(default_dirservers_string, 1) < 0) {
426
427
428
429
430
431
    log_fn(LOG_WARN,"Bug: the default dirservers internal string is corrupt.");
    return -1;
  }
  return 0;
}

Nick Mathewson's avatar
Nick Mathewson committed
432
433
/** Set <b>options</b> to a reasonable default.
 *
Roger Dingledine's avatar
Roger Dingledine committed
434
 * Call this function when we can't find any torrc config file.
435
 */
Roger Dingledine's avatar
Roger Dingledine committed
436
static int config_assign_defaults(or_options_t *options) {
437
438
439
440

  /* set them up as a client only */
  options->SocksPort = 9050;

Roger Dingledine's avatar
Roger Dingledine committed
441
442
443
  config_free_lines(options->ExitPolicy);
  options->ExitPolicy = config_line_prepend(NULL, "ExitPolicy", "reject *:*");

444
  /* plus give them a dirservers file */
445
  if(config_assign_default_dirservers() < 0)
446
447
448
449
    return -1;
  return 0;
}

Nick Mathewson's avatar
Nick Mathewson committed
450
/** Print a usage message for tor. */
451
static void print_usage(void) {
452
  printf("tor -f <torrc> [args]\n"
453
         "See man page for more options. This -h is probably obsolete.\n\n"
454
         "-b <bandwidth>\t\tbytes/second rate limiting\n"
455
         "-d <file>\t\tDebug file\n"
456
//         "-m <max>\t\tMax number of connections\n"
457
458
459
460
         "-l <level>\t\tLog level\n"
         "-r <file>\t\tList of known routers\n");
  printf("\nClient options:\n"
         "-e \"nick1 nick2 ...\"\t\tExit nodes\n"
461
         "-s <IP>\t\t\tPort to bind to for Socks\n"
462
         );
463
464
  printf("\nServer options:\n"
         "-n <nick>\t\tNickname of router\n"
465
466
467
         "-o <port>\t\tOR port to bind to\n"
         "-p <file>\t\tPID file\n"
         );
468
469
}

Nick Mathewson's avatar
Nick Mathewson committed
470
471
472
/**
 * Adjust <b>options</b> to contain a reasonable value for Address.
 */
473
int resolve_my_address(const char *address, uint32_t *addr) {
474
475
  struct in_addr in;
  struct hostent *rent;
476
  char hostname[256];
477
  int explicit_ip=1;
478

479
480
481
482
483
  tor_assert(addr);

  if(address) {
    strlcpy(hostname,address,sizeof(hostname));
  } else { /* then we need to guess our address */
484
    explicit_ip = 0; /* it's implicit */
485

486
    if(gethostname(hostname,sizeof(hostname)) < 0) {
487
488
489
      log_fn(LOG_WARN,"Error obtaining local hostname");
      return -1;
    }
490
    log_fn(LOG_DEBUG,"Guessed local host name as '%s'",hostname);
491
492
  }

493
  /* now we know hostname. resolve it and keep only the IP */
494

495
  if(tor_inet_aton(hostname, &in) == 0) {
496
497
    /* then we have to resolve it */
    explicit_ip = 0;
498
    rent = (struct hostent *)gethostbyname(hostname);
499
    if (!rent) {
500
      log_fn(LOG_WARN,"Could not resolve local Address %s. Failing.", hostname);
501
502
      return -1;
    }
Roger Dingledine's avatar
Roger Dingledine committed
503
    tor_assert(rent->h_length == 4);
504
    memcpy(&in.s_addr, rent->h_addr,rent->h_length);
505
  }
506
  if(!explicit_ip && is_internal_IP(htonl(in.s_addr))) {
507
    log_fn(LOG_WARN,"Address '%s' resolves to private IP '%s'. "
508
           "Please set the Address config option to be the IP you want to use.",
509
           hostname, inet_ntoa(in));
510
511
    return -1;
  }
512
513
  log_fn(LOG_DEBUG,"Resolved Address to %s.", inet_ntoa(in));
  *addr = ntohl(in.s_addr);
514
515
516
  return 0;
}

517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
static char *get_default_nickname(void)
{
  char localhostname[256];
  char *cp, *out, *outp;

  if(gethostname(localhostname,sizeof(localhostname)) < 0) {
    log_fn(LOG_WARN,"Error obtaining local hostname");
    return NULL;
  }
  /* Put it in lowercase; stop at the first dot. */
  for(cp = localhostname; *cp; ++cp) {
    if (*cp == '.') {
      *cp = '\0';
      break;
    }
    *cp = tolower(*cp);
  }
  /* Strip invalid characters. */
  cp = localhostname;
  out = outp = tor_malloc(strlen(localhostname)+1);
  while (*cp) {
    if (strchr(LEGAL_NICKNAME_CHARACTERS, *cp))
      *outp++ = *cp++;
    else
      cp++;
  }
  *outp = '\0';
  /* Enforce length. */
  if (strlen(out) > MAX_NICKNAME_LEN)
    out[MAX_NICKNAME_LEN]='\0';

  return out;
}

Nick Mathewson's avatar
Nick Mathewson committed
551
/** Release storage held by <b>options</b> */
552
static void free_options(or_options_t *options) {
553
  config_free_lines(options->LogOptions);
554
  tor_free(options->ContactInfo);
555
556
557
558
559
560
  tor_free(options->DebugLogFile);
  tor_free(options->DataDirectory);
  tor_free(options->RouterFile);
  tor_free(options->Nickname);
  tor_free(options->Address);
  tor_free(options->PidFile);
561
562
  tor_free(options->ExitNodes);
  tor_free(options->EntryNodes);
563
  tor_free(options->ExcludeNodes);
564
565
  tor_free(options->RendNodes);
  tor_free(options->RendExcludeNodes);
566
  tor_free(options->OutboundBindAddress);
567
  tor_free(options->RecommendedVersions);
568
569
  tor_free(options->User);
  tor_free(options->Group);
570
  config_free_lines(options->RendConfigLines);
571
572
573
574
575
  config_free_lines(options->SocksBindAddress);
  config_free_lines(options->ORBindAddress);
  config_free_lines(options->DirBindAddress);
  config_free_lines(options->ExitPolicy);
  config_free_lines(options->SocksPolicy);
576
577
  SMARTLIST_FOREACH(options->FirewallPorts, char *, cp, tor_free(cp));
  smartlist_free(options->FirewallPorts);
578
}
579

Nick Mathewson's avatar
Nick Mathewson committed
580
/** Set <b>options</b> to hold reasonable defaults for most options. */
581
static void init_options(or_options_t *options) {
582
/* give reasonable values for each option. Defaults to zero. */
583
  memset(options,0,sizeof(or_options_t));
584
  options->LogOptions = NULL;
585
586
  options->ExitNodes = tor_strdup("");
  options->EntryNodes = tor_strdup("");
587
  options->StrictEntryNodes = options->StrictExitNodes = 0;
588
  options->ExcludeNodes = tor_strdup("");
589
590
  options->RendNodes = tor_strdup("");
  options->RendExcludeNodes = tor_strdup("");
591
592
593
594
595
  options->ExitPolicy = NULL;
  options->SocksPolicy = NULL;
  options->SocksBindAddress = NULL;
  options->ORBindAddress = NULL;
  options->DirBindAddress = NULL;
596
  options->OutboundBindAddress = NULL;
597
  options->RecommendedVersions = NULL;
598
  options->PidFile = NULL; // tor_strdup("tor.pid");
599
  options->DataDirectory = NULL;
600
  options->PathlenCoinWeight = 0.3;
601
  options->MaxConn = 900;
602
  options->DirFetchPostPeriod = 600;
603
  options->KeepalivePeriod = 300;
604
  options->MaxOnionsPending = 100;
605
  options->NewCircuitPeriod = 30; /* twice a minute */
606
607
  options->BandwidthRate = 800000; /* at most 800kB/s total sustained incoming */
  options->BandwidthBurst = 10000000; /* max burst on the token bucket */
608
  options->NumCpus = 1;
609
  options->RendConfigLines = NULL;
610
  options->FirewallPorts = NULL;
611
612
}

Nick Mathewson's avatar
Nick Mathewson committed
613
614
615
/** Read a configuration file into <b>options</b>, finding the configuration
 * file location based on the command line.  After loading the options,
 * validate them for consistency. Return 0 if success, <0 if failure. */
616
int getconfig(int argc, char **argv, or_options_t *options) {
617
  struct config_line_t *cl;
618
619
620
621
  FILE *cf;
  char *fname;
  int i;
  int result = 0;
622
623
624
625
626
  static int first_load = 1;
  static char **backup_argv;
  static int backup_argc;
  char *previous_pidfile = NULL;
  int previous_runasdaemon = 0;
627
  int previous_orport = -1;
628
  int using_default_torrc;
629
630
631
632
633
634
635
636
637
638

  if(first_load) { /* first time we're called. save commandline args */
    backup_argv = argv;
    backup_argc = argc;
    first_load = 0;
  } else { /* we're reloading. need to clean up old ones first. */
    argv = backup_argv;
    argc = backup_argc;

    /* record some previous values, so we can fail if they change */
639
640
    if(options->PidFile)
      previous_pidfile = tor_strdup(options->PidFile);
641
    previous_runasdaemon = options->RunAsDaemon;
642
    previous_orport = options->ORPort;
643
644
    free_options(options);
  }
Roger Dingledine's avatar
Roger Dingledine committed
645
  init_options(options);
646

647
648
649
650
651
  if(argc > 1 && (!strcmp(argv[1], "-h") || !strcmp(argv[1],"--help"))) {
    print_usage();
    exit(0);
  }

652
653
654
655
656
  if(argc > 1 && (!strcmp(argv[1],"--version"))) {
    printf("Tor version %s.\n",VERSION);
    exit(0);
  }

657
658
659
660
661
662
/* learn config file name, get config lines, assign them */
  i = 1;
  while(i < argc-1 && strcmp(argv[i],"-f")) {
    i++;
  }
  if(i < argc-1) { /* we found one */
663
    fname = tor_strdup(argv[i+1]);
664
    using_default_torrc = 0;
665
666
667
668
669
670
671
672
673
674
675
676
  } else if (file_status(CONFDIR "/torrc")==FN_FILE) {
    /* didn't find one, try CONFDIR */
    fname = tor_strdup(CONFDIR "/torrc");
    using_default_torrc = 1;
  } else {
    char *fn = expand_filename("~/.torrc");
    if (file_status(fn)==FN_FILE) {
      fname = fn;
    } else {
      tor_free(fn);
      fname = tor_strdup(CONFDIR "/torrc");
    }
677
    using_default_torrc = 1;
678
679
680
681
  }
  log(LOG_DEBUG,"Opening config file '%s'",fname);

  cf = config_open(fname);
682
  if(!cf) {
683
    if(using_default_torrc == 1) {
684
      log(LOG_NOTICE, "Configuration file '%s' not present, using reasonable defaults.",fname);
685
686
      tor_free(fname);
      if(config_assign_defaults(options) < 0) {
687
        return -1;
688
      }
689
690
    } else {
      log(LOG_WARN, "Unable to open configuration file '%s'.",fname);
691
      tor_free(fname);
692
693
694
      return -1;
    }
  } else { /* it opened successfully. use it. */
695
    tor_free(fname);
696
697
    cl = config_get_lines(cf);
    if(!cl) return -1;
698
699
    if(config_assign(options,cl) < 0)
      return -1;
700
701
    config_free_lines(cl);
    config_close(cf);
702
  }
703

704
705
/* go through command-line variables too */
  cl = config_get_commandlines(argc,argv);
706
707
  if(config_assign(options,cl) < 0)
    return -1;
708
709
710
711
  config_free_lines(cl);

/* Validate options */

712
  /* first check if any of the previous options have changed but aren't allowed to */
713
714
715
716
717
718
719
720
721
722
723
724
  if(previous_pidfile && strcmp(previous_pidfile,options->PidFile)) {
    log_fn(LOG_WARN,"During reload, PidFile changed from %s to %s. Failing.",
           previous_pidfile, options->PidFile);
    return -1;
  }
  tor_free(previous_pidfile);

  if(previous_runasdaemon && !options->RunAsDaemon) {
    log_fn(LOG_WARN,"During reload, change from RunAsDaemon=1 to =0 not allowed. Failing.");
    return -1;
  }

725
  if(previous_orport == 0 && options->ORPort > 0) {
Roger Dingledine's avatar
Roger Dingledine committed
726
    log_fn(LOG_WARN,"During reload, change from ORPort=0 to >0 not allowed. Failing.");
727
728
729
    return -1;
  }

730
  if(options->ORPort < 0) {
Roger Dingledine's avatar
Roger Dingledine committed
731
    log(LOG_WARN,"ORPort option can't be negative.");
732
733
734
    result = -1;
  }

735
  if (options->Nickname == NULL) {
736
737
738
739
740
    if(server_mode()) {
      if (!(options->Nickname = get_default_nickname()))
        return -1;
      log_fn(LOG_NOTICE, "Choosing default nickname %s", options->Nickname);
    }
741
742
743
744
745
746
747
748
749
750
  } else {
    if (strspn(options->Nickname, LEGAL_NICKNAME_CHARACTERS) !=
        strlen(options->Nickname)) {
      log_fn(LOG_WARN, "Nickname '%s' contains illegal characters.", options->Nickname);
      result = -1;
    }
    if (strlen(options->Nickname) > MAX_NICKNAME_LEN) {
      log_fn(LOG_WARN, "Nickname '%s' has more than %d characters.",
             options->Nickname, MAX_NICKNAME_LEN);
      result = -1;
751
    }
752
753
  }

754
755
756
757
  if(server_mode()) {
    /* confirm that our address isn't broken, so we can complain now */
    uint32_t tmp;
    if(resolve_my_address(options->Address, &tmp) < 0)
758
      result = -1;
759
760
  }

761
762
  if(options->SocksPort < 0) {
    log(LOG_WARN,"SocksPort option can't be negative.");
763
764
765
    result = -1;
  }

766
767
768
  if(options->SocksPort == 0 && options->ORPort == 0) {
    log(LOG_WARN,"SocksPort and ORPort are both undefined? Quitting.");
    result = -1;
Roger Dingledine's avatar
Roger Dingledine committed
769
  }
770

771
  if(options->DirPort < 0) {
Roger Dingledine's avatar
Roger Dingledine committed
772
    log(LOG_WARN,"DirPort option can't be negative.");
773
774
775
    result = -1;
  }

776
777
778
779
780
781
782
783
  if(options->StrictExitNodes && !strlen(options->ExitNodes)) {
    log(LOG_WARN,"StrictExitNodes set, but no ExitNodes listed.");
  }

  if(options->StrictEntryNodes && !strlen(options->EntryNodes)) {
    log(LOG_WARN,"StrictEntryNodes set, but no EntryNodes listed.");
  }

Roger Dingledine's avatar
Roger Dingledine committed
784
  if(options->AuthoritativeDir && options->RecommendedVersions == NULL) {
785
786
787
788
    log(LOG_WARN,"Directory servers must configure RecommendedVersions.");
    result = -1;
  }

789
790
791
792
793
  if(options->AuthoritativeDir && !options->DirPort) {
    log(LOG_WARN,"Running as authoritative directory, but no DirPort set.");
    result = -1;
  }

Roger Dingledine's avatar
Roger Dingledine committed
794
795
796
797
  if(options->AuthoritativeDir && !options->ORPort) {
    log(LOG_WARN,"Running as authoritative directory, but no ORPort set.");
    result = -1;
  }
798

Roger Dingledine's avatar
Roger Dingledine committed
799
800
801
802
  if(options->AuthoritativeDir && options->ClientOnly) {
    log(LOG_WARN,"Running as authoritative directory, but ClientOnly also set.");
    result = -1;
  }
803

804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
  if(options->FascistFirewall && !options->FirewallPorts) {
    options->FirewallPorts = smartlist_create();
    smartlist_add(options->FirewallPorts, "80");
    smartlist_add(options->FirewallPorts, "443");
  }
  if(options->FirewallPorts) {
    SMARTLIST_FOREACH(options->FirewallPorts, const char *, cp,
    { i = atoi(cp); 
      if (i < 1 || i > 65535) {
        log(LOG_WARN, "Port %s out of range in FirewallPorts", cp);
        result=-1;
      }
    });
  }

819
  if(options->SocksPort >= 1 &&
820
821
     (options->PathlenCoinWeight < 0.0 || options->PathlenCoinWeight >= 1.0)) {
    log(LOG_WARN,"PathlenCoinWeight option must be >=0.0 and <1.0.");
822
823
824
    result = -1;
  }

825
  if(options->MaxConn < 1) {
Roger Dingledine's avatar
Roger Dingledine committed
826
    log(LOG_WARN,"MaxConn option must be a non-zero positive integer.");
827
828
829
830
    result = -1;
  }

  if(options->MaxConn >= MAXCONNECTIONS) {
Roger Dingledine's avatar
Roger Dingledine committed
831
    log(LOG_WARN,"MaxConn option must be less than %d.", MAXCONNECTIONS);
832
833
834
    result = -1;
  }

835
  if(options->DirFetchPostPeriod < 1) {
Roger Dingledine's avatar
Roger Dingledine committed
836
    log(LOG_WARN,"DirFetchPostPeriod option must be positive.");
837
838
    result = -1;
  }
839
840
841
842
  if(options->DirFetchPostPeriod > MIN_ONION_KEY_LIFETIME/2) {
    log(LOG_WARN,"DirFetchPostPeriod is too large; clipping.");
    options->DirFetchPostPeriod = MIN_ONION_KEY_LIFETIME/2;
  }
843
844

  if(options->KeepalivePeriod < 1) {
Roger Dingledine's avatar
Roger Dingledine committed
845
    log(LOG_WARN,"KeepalivePeriod option must be positive.");
846
847
848
    result = -1;
  }

849
850
851
852
  /* XXX look at the various nicknamelists and make sure they're
   * valid and don't have hostnames that are too long.
   */

853
854
855
856
  if (rend_config_services(options) < 0) {
    result = -1;
  }

857
  return result;
858
859
}

860
static int add_single_log(struct config_line_t *level_opt,
861
862
863
864
865
866
867
868
869
870
871
872
                           struct config_line_t *file_opt,
                           int isDaemon)
{
  int levelMin=-1, levelMax=-1;
  char *cp, *tmp_sev;

  if (level_opt) {
    cp = strchr(level_opt->value, '-');
    if (cp) {
      tmp_sev = tor_strndup(level_opt->value, cp - level_opt->value);
      levelMin = parse_log_level(tmp_sev);
      if (levelMin<0) {
873
874
        log_fn(LOG_WARN, "Unrecognized log severity '%s': must be one of err|warn|notice|info|debug", tmp_sev);
        return -1;
875
876
877
878
      }
      tor_free(tmp_sev);
      levelMax = parse_log_level(cp+1);
      if (levelMax<0) {
879
880
        log_fn(LOG_WARN, "Unrecognized log severity '%s': must be one of err|warn|notice|info|debug", cp+1);
        return -1;
881
882
883
884
      }
    } else {
      levelMin = parse_log_level(level_opt->value);
      if (levelMin<0) {
885
886
887
        log_fn(LOG_WARN, "Unrecognized log severity '%s': must be one of err|warn|notice|info|debug", level_opt->value);
        return -1;

888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
      }
    }
  }
  if (levelMin < 0 && levelMax < 0) {
    levelMin = LOG_NOTICE;
    levelMax = LOG_ERR;
  } else if (levelMin < 0) {
    levelMin = levelMax;
  } else {
    levelMax = LOG_ERR;
  }
  if (file_opt) {
    if (add_file_log(levelMin, levelMax, file_opt->value) < 0) {
      log_fn(LOG_WARN, "Cannot write to LogFile '%s': %s.", file_opt->value,
             strerror(errno));
903
      return -1;
904
905
906
907
    }
    log_fn(LOG_NOTICE, "Successfully opened LogFile '%s', redirecting output.",
           file_opt->value);
  } else if (!isDaemon) {
908
    add_stream_log(levelMin, levelMax, "<stdout>", stdout);
909
    close_temp_logs();
910
  }
911
  return 0;
912
913
914
915
916
}

/**
 * Initialize the logs based on the configuration file.
 */
917
int config_init_logs(or_options_t *options)
918
919
920
921
922
{
  /* The order of options is:  Level? (File Level?)+
   */
  struct config_line_t *opt = options->LogOptions;

923
924
925
926
  /* Special case if no options are given. */
  if (!opt) {
    add_stream_log(LOG_NOTICE, LOG_ERR, "<stdout>", stdout);
    close_temp_logs();
Roger Dingledine's avatar
Roger Dingledine committed
927
928
    /* don't return yet, in case we want to do a debuglogfile below */
  }
929

930
931
932
  /* Special case for if first option is LogLevel. */
  if (opt && !strcasecmp(opt->key, "LogLevel")) {
    if (opt->next && !strcasecmp(opt->next->key, "LogFile")) {
933
934
      if (add_single_log(opt, opt->next, options->RunAsDaemon)<0)
        return -1;
935
936
      opt = opt->next->next;
    } else if (!opt->next) {
937
938
      if (add_single_log(opt, NULL, options->RunAsDaemon)<0)
        return -1;
939
      opt = opt->next;
940
941
    } else {
      ; /* give warning below */
942
943
944
945
946
947
948
949
    }
  }

  while (opt) {
    if (!strcasecmp(opt->key, "LogLevel")) {
      log_fn(LOG_WARN, "Two LogLevel options in a row without intervening LogFile");
      opt = opt->next;
    } else {
950
      tor_assert(!strcasecmp(opt->key, "LogFile"));
951
952
      if (opt->next && !strcasecmp(opt->next->key, "LogLevel")) {
        /* LogFile followed by LogLevel */
953
954
        if (add_single_log(opt->next, opt, options->RunAsDaemon)<0)
          return -1;
955
956
957
        opt = opt->next->next;
      } else {
        /* LogFile followed by LogFile or end of list. */
958
959
        if (add_single_log(NULL, opt, options->RunAsDaemon)<0)
          return -1;
960
961
962
963
964
965
966
        opt = opt->next;
      }
    }
  }

  if (options->DebugLogFile) {
    log_fn(LOG_WARN, "DebugLogFile is deprecated; use LogFile and LogLevel instead");
967
968
    if (add_file_log(LOG_DEBUG, LOG_ERR, options->DebugLogFile)<0)
      return -1;
969
  }
970
  return 0;
971
972
}

973
/** XXX008 DOCDOC */
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
void
config_parse_exit_policy(struct config_line_t *cfg,
                         struct exit_policy_t **dest)
{
  struct exit_policy_t **nextp;
  char *e, *s;
  int last=0;
  char line[1024];

  if (!cfg)
    return;
  nextp = dest;
  while (*nextp)
    nextp = &((*nextp)->next);

  for (; cfg; cfg = cfg->next) {
    s = cfg->value;
    for (;;) {
      e = strchr(s,',');
      if(!e) {
        last = 1;
        strncpy(line,s,1023);
      } else {
        memcpy(line,s, ((e-s)<1023)?(e-s):1023);
      line[e-s] = 0;
      }
      line[1023]=0;