Trace.cpp 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560
  1. /*
  2. * ZeroTier One - Network Virtualization Everywhere
  3. * Copyright (C) 2011-2018 ZeroTier, Inc. https://www.zerotier.com/
  4. *
  5. * This program is free software: you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation, either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. * --
  19. *
  20. * You can be released from the requirements of the license by purchasing
  21. * a commercial license. Buying such a license is mandatory as soon as you
  22. * develop commercial closed-source software that incorporates or links
  23. * directly against ZeroTier software without disclosing the source code
  24. * of your own application.
  25. */
  26. //#define ZT_TRACE
  27. #include <stdio.h>
  28. #include <stdarg.h>
  29. #include "Trace.hpp"
  30. #include "RuntimeEnvironment.hpp"
  31. #include "Switch.hpp"
  32. #include "Node.hpp"
  33. #include "Utils.hpp"
  34. #include "Dictionary.hpp"
  35. #include "CertificateOfMembership.hpp"
  36. #include "CertificateOfOwnership.hpp"
  37. #include "Tag.hpp"
  38. #include "Capability.hpp"
  39. #include "Revocation.hpp"
  40. namespace ZeroTier {
  41. #ifdef ZT_TRACE
  42. static void ZT_LOCAL_TRACE(void *const tPtr,const RuntimeEnvironment *const RR,const char *const fmt,...)
  43. {
  44. char traceMsgBuf[1024];
  45. va_list ap;
  46. va_start(ap,fmt);
  47. vsnprintf(traceMsgBuf,sizeof(traceMsgBuf),fmt,ap);
  48. va_end(ap);
  49. traceMsgBuf[sizeof(traceMsgBuf) - 1] = (char)0;
  50. RR->node->postEvent(tPtr,ZT_EVENT_TRACE,traceMsgBuf);
  51. }
  52. #else
  53. #define ZT_LOCAL_TRACE(...)
  54. #endif
  55. void Trace::resettingPathsInScope(void *const tPtr,const Address &reporter,const InetAddress &reporterPhysicalAddress,const InetAddress &myPhysicalAddress,const InetAddress::IpScope scope)
  56. {
  57. char tmp[128];
  58. ZT_LOCAL_TRACE(tPtr,RR,"RESET and revalidate paths in scope %d; new phy address %s reported by trusted peer %.10llx",(int)scope,myPhysicalAddress.toIpString(tmp),reporter.toInt());
  59. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  60. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__RESETTING_PATHS_IN_SCOPE_S);
  61. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,reporter);
  62. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,reporterPhysicalAddress.toString(tmp));
  63. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_PHYADDR,myPhysicalAddress.toString(tmp));
  64. d.add(ZT_REMOTE_TRACE_FIELD__IP_SCOPE,(uint64_t)scope);
  65. if (_globalTarget)
  66. _send(tPtr,d,_globalTarget);
  67. _spamToAllNetworks(tPtr,d,Trace::LEVEL_NORMAL);
  68. }
  69. void Trace::peerConfirmingUnknownPath(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &path,const uint64_t packetId,const Packet::Verb verb)
  70. {
  71. char tmp[128];
  72. if (!path) return; // sanity check
  73. ZT_LOCAL_TRACE(tPtr,RR,"trying unknown path %s to %.10llx (packet %.16llx verb %d local socket %lld network %.16llx)",path->address().toString(tmp),peer.address().toInt(),packetId,(double)verb,path->localSocket(),networkId);
  74. std::pair<Address,Trace::Level> byn;
  75. if (networkId) { Mutex::Lock l(_byNet_m); _byNet.get(networkId,byn); }
  76. if ((_globalTarget)||(byn.first)) {
  77. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  78. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PEER_CONFIRMING_UNKNOWN_PATH_S);
  79. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  80. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  81. if (networkId)
  82. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,networkId);
  83. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,peer.address());
  84. if (path) {
  85. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  86. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  87. }
  88. if (_globalTarget)
  89. _send(tPtr,d,_globalTarget);
  90. if (byn.first)
  91. _send(tPtr,d,byn.first);
  92. }
  93. }
  94. void Trace::peerLinkNowRedundant(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &newPath)
  95. {
  96. ZT_LOCAL_TRACE(tPtr,RR,"link to peer %.10llx on network %.16llx is fully redundant",peer.address().toInt(),networkId);
  97. }
  98. void Trace::peerLinkNoLongerRedundant(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &newPath)
  99. {
  100. ZT_LOCAL_TRACE(tPtr,RR,"link to peer %.10llx on network %.16llx is no longer redundant",peer.address().toInt(),networkId);
  101. }
  102. void Trace::peerLinkBalanced(void *const tPtr,const uint64_t networkId,Peer &peer)
  103. {
  104. ZT_LOCAL_TRACE(tPtr,RR,"link to peer %.10llx on network %.16llx is balanced",peer.address().toInt(),networkId);
  105. }
  106. void Trace::peerLinkImbalanced(void *const tPtr,const uint64_t networkId,Peer &peer)
  107. {
  108. ZT_LOCAL_TRACE(tPtr,RR,"link to peer %.10llx on network %.16llx is unbalanced",peer.address().toInt(),networkId);
  109. }
  110. void Trace::peerLearnedNewPath(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &newPath,const uint64_t packetId)
  111. {
  112. char tmp[128];
  113. if (!newPath) return; // sanity check
  114. ZT_LOCAL_TRACE(tPtr,RR,"learned new path %s to %.10llx (packet %.16llx local socket %lld network %.16llx)",newPath->address().toString(tmp),peer.address().toInt(),packetId,newPath->localSocket(),networkId);
  115. std::pair<Address,Trace::Level> byn;
  116. if (networkId) { Mutex::Lock l(_byNet_m); _byNet.get(networkId,byn); }
  117. if ((_globalTarget)||(byn.first)) {
  118. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  119. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PEER_LEARNED_NEW_PATH_S);
  120. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  121. if (networkId)
  122. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,networkId);
  123. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,peer.address());
  124. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,newPath->address().toString(tmp));
  125. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,newPath->localSocket());
  126. if (_globalTarget)
  127. _send(tPtr,d,_globalTarget);
  128. if (byn.first)
  129. _send(tPtr,d,byn.first);
  130. }
  131. }
  132. void Trace::peerRedirected(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &newPath)
  133. {
  134. char tmp[128];
  135. if (!newPath) return; // sanity check
  136. ZT_LOCAL_TRACE(tPtr,RR,"explicit redirect from %.10llx to path %s",peer.address().toInt(),newPath->address().toString(tmp));
  137. std::pair<Address,Trace::Level> byn;
  138. if (networkId) { Mutex::Lock l(_byNet_m); _byNet.get(networkId,byn); }
  139. if ((_globalTarget)||(byn.first)) {
  140. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  141. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PEER_REDIRECTED_S);
  142. if (networkId)
  143. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,networkId);
  144. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,peer.address());
  145. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,newPath->address().toString(tmp));
  146. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,newPath->localSocket());
  147. if (_globalTarget)
  148. _send(tPtr,d,_globalTarget);
  149. if (byn.first)
  150. _send(tPtr,d,byn.first);
  151. }
  152. }
  153. void Trace::outgoingNetworkFrameDropped(void *const tPtr,const SharedPtr<Network> &network,const MAC &sourceMac,const MAC &destMac,const unsigned int etherType,const unsigned int vlanId,const unsigned int frameLen,const char *reason)
  154. {
  155. #ifdef ZT_TRACE
  156. char tmp[128],tmp2[128];
  157. #endif
  158. if (!network) return; // sanity check
  159. ZT_LOCAL_TRACE(tPtr,RR,"%.16llx DROP frame %s -> %s etherType %.4x size %u (%s)",network->id(),sourceMac.toString(tmp),destMac.toString(tmp2),etherType,frameLen,(reason) ? reason : "unknown reason");
  160. std::pair<Address,Trace::Level> byn;
  161. { Mutex::Lock l(_byNet_m); _byNet.get(network->id(),byn); }
  162. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE)) ) {
  163. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  164. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__OUTGOING_NETWORK_FRAME_DROPPED_S);
  165. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network->id());
  166. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_MAC,sourceMac.toInt());
  167. d.add(ZT_REMOTE_TRACE_FIELD__DEST_MAC,destMac.toInt());
  168. d.add(ZT_REMOTE_TRACE_FIELD__ETHERTYPE,(uint64_t)etherType);
  169. d.add(ZT_REMOTE_TRACE_FIELD__VLAN_ID,(uint64_t)vlanId);
  170. d.add(ZT_REMOTE_TRACE_FIELD__FRAME_LENGTH,(uint64_t)frameLen);
  171. if (reason)
  172. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  173. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE))
  174. _send(tPtr,d,_globalTarget);
  175. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE))
  176. _send(tPtr,d,byn.first);
  177. }
  178. }
  179. void Trace::incomingNetworkAccessDenied(void *const tPtr,const SharedPtr<Network> &network,const SharedPtr<Path> &path,const uint64_t packetId,const unsigned int packetLength,const Address &source,const Packet::Verb verb,bool credentialsRequested)
  180. {
  181. char tmp[128];
  182. if (!network) return; // sanity check
  183. ZT_LOCAL_TRACE(tPtr,RR,"%.16llx DENIED packet from %.10llx(%s) verb %d size %u%s",network->id(),source.toInt(),(path) ? (path->address().toString(tmp)) : "???",(int)verb,packetLength,credentialsRequested ? " (credentials requested)" : " (credentials not requested)");
  184. std::pair<Address,Trace::Level> byn;
  185. { Mutex::Lock l(_byNet_m); _byNet.get(network->id(),byn); }
  186. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE)) ) {
  187. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  188. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__INCOMING_NETWORK_ACCESS_DENIED_S);
  189. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  190. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  191. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  192. if (path) {
  193. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  194. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  195. }
  196. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network->id());
  197. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE))
  198. _send(tPtr,d,_globalTarget);
  199. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE))
  200. _send(tPtr,d,byn.first);
  201. }
  202. }
  203. void Trace::incomingNetworkFrameDropped(void *const tPtr,const SharedPtr<Network> &network,const SharedPtr<Path> &path,const uint64_t packetId,const unsigned int packetLength,const Address &source,const Packet::Verb verb,const MAC &sourceMac,const MAC &destMac,const char *reason)
  204. {
  205. char tmp[128];
  206. if (!network) return; // sanity check
  207. ZT_LOCAL_TRACE(tPtr,RR,"%.16llx DROPPED frame from %.10llx(%s) verb %d size %u",network->id(),source.toInt(),(path) ? (path->address().toString(tmp)) : "???",(int)verb,packetLength);
  208. std::pair<Address,Trace::Level> byn;
  209. { Mutex::Lock l(_byNet_m); _byNet.get(network->id(),byn); }
  210. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE)) ) {
  211. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  212. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__INCOMING_NETWORK_FRAME_DROPPED_S);
  213. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  214. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  215. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  216. if (path) {
  217. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  218. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  219. }
  220. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network->id());
  221. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_MAC,sourceMac.toInt());
  222. d.add(ZT_REMOTE_TRACE_FIELD__DEST_MAC,destMac.toInt());
  223. if (reason)
  224. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  225. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE))
  226. _send(tPtr,d,_globalTarget);
  227. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE))
  228. _send(tPtr,d,byn.first);
  229. }
  230. }
  231. void Trace::incomingPacketMessageAuthenticationFailure(void *const tPtr,const SharedPtr<Path> &path,const uint64_t packetId,const Address &source,const unsigned int hops,const char *reason)
  232. {
  233. char tmp[128];
  234. ZT_LOCAL_TRACE(tPtr,RR,"MAC failed for packet %.16llx from %.10llx(%s)",packetId,source.toInt(),(path) ? path->address().toString(tmp) : "???");
  235. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  236. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  237. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PACKET_MAC_FAILURE_S);
  238. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  239. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_HOPS,(uint64_t)hops);
  240. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  241. if (path) {
  242. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  243. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  244. }
  245. if (reason)
  246. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  247. _send(tPtr,d,_globalTarget);
  248. }
  249. }
  250. void Trace::incomingPacketInvalid(void *const tPtr,const SharedPtr<Path> &path,const uint64_t packetId,const Address &source,const unsigned int hops,const Packet::Verb verb,const char *reason)
  251. {
  252. char tmp[128];
  253. ZT_LOCAL_TRACE(tPtr,RR,"INVALID packet %.16llx from %.10llx(%s) (%s)",packetId,source.toInt(),(path) ? path->address().toString(tmp) : "???",(reason) ? reason : "unknown reason");
  254. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  255. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  256. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PACKET_INVALID_S);
  257. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  258. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  259. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  260. if (path) {
  261. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  262. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  263. }
  264. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_HOPS,(uint64_t)hops);
  265. if (reason)
  266. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  267. _send(tPtr,d,_globalTarget);
  268. }
  269. }
  270. void Trace::incomingPacketDroppedHELLO(void *const tPtr,const SharedPtr<Path> &path,const uint64_t packetId,const Address &source,const char *reason)
  271. {
  272. char tmp[128];
  273. ZT_LOCAL_TRACE(tPtr,RR,"DROPPED HELLO from %.10llx(%s) (%s)",source.toInt(),(path) ? path->address().toString(tmp) : "???",(reason) ? reason : "???");
  274. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  275. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  276. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PACKET_INVALID_S);
  277. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  278. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  279. if (path) {
  280. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  281. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  282. }
  283. if (reason)
  284. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  285. _send(tPtr,d,_globalTarget);
  286. }
  287. }
  288. void Trace::networkConfigRequestSent(void *const tPtr,const Network &network,const Address &controller)
  289. {
  290. ZT_LOCAL_TRACE(tPtr,RR,"requesting configuration for network %.16llx",network.id());
  291. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  292. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  293. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__NETWORK_CONFIG_REQUEST_SENT_S);
  294. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network.id());
  295. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_CONTROLLER_ID,controller);
  296. _send(tPtr,d,_globalTarget);
  297. }
  298. }
  299. void Trace::networkFilter(
  300. void *const tPtr,
  301. const Network &network,
  302. const RuleResultLog &primaryRuleSetLog,
  303. const RuleResultLog *const matchingCapabilityRuleSetLog,
  304. const Capability *const matchingCapability,
  305. const Address &ztSource,
  306. const Address &ztDest,
  307. const MAC &macSource,
  308. const MAC &macDest,
  309. const uint8_t *const frameData,
  310. const unsigned int frameLen,
  311. const unsigned int etherType,
  312. const unsigned int vlanId,
  313. const bool noTee,
  314. const bool inbound,
  315. const int accept)
  316. {
  317. std::pair<Address,Trace::Level> byn;
  318. { Mutex::Lock l(_byNet_m); _byNet.get(network.id(),byn); }
  319. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_RULES)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_RULES)) ) {
  320. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  321. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__NETWORK_FILTER_TRACE_S);
  322. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network.id());
  323. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_ZTADDR,ztSource);
  324. d.add(ZT_REMOTE_TRACE_FIELD__DEST_ZTADDR,ztDest);
  325. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_MAC,macSource.toInt());
  326. d.add(ZT_REMOTE_TRACE_FIELD__DEST_MAC,macDest.toInt());
  327. d.add(ZT_REMOTE_TRACE_FIELD__ETHERTYPE,(uint64_t)etherType);
  328. d.add(ZT_REMOTE_TRACE_FIELD__VLAN_ID,(uint64_t)vlanId);
  329. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_FLAG_NOTEE,noTee ? "1" : "0");
  330. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_FLAG_INBOUND,inbound ? "1" : "0");
  331. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_RESULT,(int64_t)accept);
  332. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_BASE_RULE_LOG,(const char *)primaryRuleSetLog.data(),(int)primaryRuleSetLog.sizeBytes());
  333. if (matchingCapabilityRuleSetLog)
  334. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_CAP_RULE_LOG,(const char *)matchingCapabilityRuleSetLog->data(),(int)matchingCapabilityRuleSetLog->sizeBytes());
  335. if (matchingCapability)
  336. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_CAP_ID,(uint64_t)matchingCapability->id());
  337. d.add(ZT_REMOTE_TRACE_FIELD__FRAME_LENGTH,(uint64_t)frameLen);
  338. if (frameLen > 0)
  339. d.add(ZT_REMOTE_TRACE_FIELD__FRAME_DATA,(const char *)frameData,(frameLen > 256) ? (int)256 : (int)frameLen);
  340. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_RULES))
  341. _send(tPtr,d,_globalTarget);
  342. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_RULES))
  343. _send(tPtr,d,byn.first);
  344. }
  345. }
  346. void Trace::credentialRejected(void *const tPtr,const CertificateOfMembership &c,const char *reason)
  347. {
  348. std::pair<Address,Trace::Level> byn;
  349. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  350. if ((_globalTarget)||(byn.first)) {
  351. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  352. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  353. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  354. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  355. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  356. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  357. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  358. if (reason)
  359. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  360. if (_globalTarget)
  361. _send(tPtr,d,_globalTarget);
  362. if (byn.first)
  363. _send(tPtr,d,byn.first);
  364. }
  365. }
  366. void Trace::credentialRejected(void *const tPtr,const CertificateOfOwnership &c,const char *reason)
  367. {
  368. std::pair<Address,Trace::Level> byn;
  369. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  370. if ((_globalTarget)||(byn.first)) {
  371. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  372. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  373. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  374. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  375. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  376. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  377. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  378. if (reason)
  379. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  380. if (_globalTarget)
  381. _send(tPtr,d,_globalTarget);
  382. if (byn.first)
  383. _send(tPtr,d,byn.first);
  384. }
  385. }
  386. void Trace::credentialRejected(void *const tPtr,const Capability &c,const char *reason)
  387. {
  388. std::pair<Address,Trace::Level> byn;
  389. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  390. if ((_globalTarget)||(byn.first)) {
  391. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  392. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  393. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  394. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  395. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  396. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  397. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  398. if (reason)
  399. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  400. if (_globalTarget)
  401. _send(tPtr,d,_globalTarget);
  402. if (byn.first)
  403. _send(tPtr,d,byn.first);
  404. }
  405. }
  406. void Trace::credentialRejected(void *const tPtr,const Tag &c,const char *reason)
  407. {
  408. std::pair<Address,Trace::Level> byn;
  409. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  410. if ((_globalTarget)||(byn.first)) {
  411. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  412. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  413. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  414. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  415. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  416. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  417. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  418. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_INFO,(uint64_t)c.value());
  419. if (reason)
  420. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  421. if (_globalTarget)
  422. _send(tPtr,d,_globalTarget);
  423. if (byn.first)
  424. _send(tPtr,d,byn.first);
  425. }
  426. }
  427. void Trace::credentialRejected(void *const tPtr,const Revocation &c,const char *reason)
  428. {
  429. std::pair<Address,Trace::Level> byn;
  430. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  431. if ((_globalTarget)||(byn.first)) {
  432. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  433. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  434. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  435. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  436. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  437. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_REVOCATION_TARGET,c.target());
  438. if (reason)
  439. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  440. if (_globalTarget)
  441. _send(tPtr,d,_globalTarget);
  442. if (byn.first)
  443. _send(tPtr,d,byn.first);
  444. }
  445. }
  446. void Trace::updateMemoizedSettings()
  447. {
  448. _globalTarget = RR->node->remoteTraceTarget();
  449. _globalLevel = RR->node->remoteTraceLevel();
  450. const std::vector< SharedPtr<Network> > nws(RR->node->allNetworks());
  451. {
  452. Mutex::Lock l(_byNet_m);
  453. _byNet.clear();
  454. for(std::vector< SharedPtr<Network> >::const_iterator n(nws.begin());n!=nws.end();++n) {
  455. const Address dest((*n)->config().remoteTraceTarget);
  456. if (dest) {
  457. std::pair<Address,Trace::Level> &m = _byNet[(*n)->id()];
  458. m.first = dest;
  459. m.second = (*n)->config().remoteTraceLevel;
  460. }
  461. }
  462. }
  463. }
  464. void Trace::_send(void *const tPtr,const Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> &d,const Address &dest)
  465. {
  466. Packet outp(dest,RR->identity.address(),Packet::VERB_REMOTE_TRACE);
  467. outp.appendCString(d.data());
  468. outp.compress();
  469. RR->sw->send(tPtr,outp,true);
  470. }
  471. void Trace::_spamToAllNetworks(void *const tPtr,const Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> &d,const Level level)
  472. {
  473. Mutex::Lock l(_byNet_m);
  474. Hashtable< uint64_t,std::pair< Address,Trace::Level > >::Iterator i(_byNet);
  475. uint64_t *k = (uint64_t *)0;
  476. std::pair<Address,Trace::Level> *v = (std::pair<Address,Trace::Level> *)0;
  477. while (i.next(k,v)) {
  478. if ((v)&&(v->first)&&((int)v->second >= (int)level))
  479. _send(tPtr,d,v->first);
  480. }
  481. }
  482. } // namespace ZeroTier