Trace.cpp 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548
  1. /*
  2. * Copyright (c)2019 ZeroTier, Inc.
  3. *
  4. * Use of this software is governed by the Business Source License included
  5. * in the LICENSE.TXT file in the project's root directory.
  6. *
  7. * Change Date: 2023-01-01
  8. *
  9. * On the date above, in accordance with the Business Source License, use
  10. * of this software will be governed by version 2.0 of the Apache License.
  11. */
  12. /****/
  13. //#define ZT_TRACE
  14. #include <stdio.h>
  15. #include <stdarg.h>
  16. #include "Trace.hpp"
  17. #include "RuntimeEnvironment.hpp"
  18. #include "Switch.hpp"
  19. #include "Node.hpp"
  20. #include "Utils.hpp"
  21. #include "Dictionary.hpp"
  22. #include "CertificateOfMembership.hpp"
  23. #include "CertificateOfOwnership.hpp"
  24. #include "Tag.hpp"
  25. #include "Capability.hpp"
  26. #include "Revocation.hpp"
  27. #include "../include/ZeroTierDebug.h"
  28. namespace ZeroTier {
  29. #ifdef ZT_TRACE
  30. static void ZT_LOCAL_TRACE(void *const tPtr,const RuntimeEnvironment *const RR,const char *const fmt,...)
  31. {
  32. char traceMsgBuf[1024];
  33. va_list ap;
  34. va_start(ap,fmt);
  35. vsnprintf(traceMsgBuf,sizeof(traceMsgBuf),fmt,ap);
  36. va_end(ap);
  37. traceMsgBuf[sizeof(traceMsgBuf) - 1] = (char)0;
  38. RR->node->postEvent(tPtr,ZT_EVENT_TRACE,traceMsgBuf);
  39. }
  40. #else
  41. #define ZT_LOCAL_TRACE(...)
  42. #endif
  43. void Trace::resettingPathsInScope(void *const tPtr,const Address &reporter,const InetAddress &reporterPhysicalAddress,const InetAddress &myPhysicalAddress,const InetAddress::IpScope scope)
  44. {
  45. char tmp[128];
  46. ZT_LOCAL_TRACE(tPtr,RR,"RESET and revalidate paths in scope %d; new phy address %s reported by trusted peer %.10llx",(int)scope,myPhysicalAddress.toIpString(tmp),reporter.toInt());
  47. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  48. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__RESETTING_PATHS_IN_SCOPE_S);
  49. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,reporter);
  50. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,reporterPhysicalAddress.toString(tmp));
  51. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_PHYADDR,myPhysicalAddress.toString(tmp));
  52. d.add(ZT_REMOTE_TRACE_FIELD__IP_SCOPE,(uint64_t)scope);
  53. if (_globalTarget)
  54. _send(tPtr,d,_globalTarget);
  55. _spamToAllNetworks(tPtr,d,Trace::LEVEL_NORMAL);
  56. }
  57. void Trace::peerConfirmingUnknownPath(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &path,const uint64_t packetId,const Packet::Verb verb)
  58. {
  59. char tmp[128];
  60. if (!path) return; // sanity check
  61. ZT_LOCAL_TRACE(tPtr,RR,"trying unknown path %s to %.10llx (packet %.16llx verb %d local socket %lld network %.16llx)",path->address().toString(tmp),peer.address().toInt(),packetId,(double)verb,path->localSocket(),networkId);
  62. std::pair<Address,Trace::Level> byn;
  63. if (networkId) { Mutex::Lock l(_byNet_m); _byNet.get(networkId,byn); }
  64. if ((_globalTarget)||(byn.first)) {
  65. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  66. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PEER_CONFIRMING_UNKNOWN_PATH_S);
  67. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  68. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  69. if (networkId)
  70. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,networkId);
  71. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,peer.address());
  72. if (path) {
  73. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  74. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  75. }
  76. if (_globalTarget)
  77. _send(tPtr,d,_globalTarget);
  78. if (byn.first)
  79. _send(tPtr,d,byn.first);
  80. }
  81. }
  82. void Trace::peerLinkNowRedundant(void *const tPtr,Peer &peer)
  83. {
  84. ZT_LOCAL_TRACE(tPtr,RR,"link to peer %.10llx is fully redundant",peer.address().toInt());
  85. }
  86. void Trace::peerLinkNoLongerRedundant(void *const tPtr,Peer &peer)
  87. {
  88. ZT_LOCAL_TRACE(tPtr,RR,"link to peer %.10llx is no longer redundant",peer.address().toInt());
  89. }
  90. void Trace::peerLinkAggregateStatistics(void *const tPtr,Peer &peer)
  91. {
  92. ZT_LOCAL_TRACE(tPtr,RR,"link to peer %.10llx is composed of (%d) physical paths %s, has packet delay variance (%.0f ms), mean latency (%.0f ms)",
  93. peer.address().toInt(),
  94. peer.aggregateLinkPhysicalPathCount(),
  95. peer.interfaceListStr(),
  96. peer.computeAggregateLinkPacketDelayVariance(),
  97. peer.computeAggregateLinkMeanLatency());
  98. }
  99. void Trace::peerLearnedNewPath(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &newPath,const uint64_t packetId)
  100. {
  101. char tmp[128];
  102. if (!newPath) return; // sanity check
  103. ZT_LOCAL_TRACE(tPtr,RR,"learned new path %s to %.10llx (packet %.16llx local socket %lld network %.16llx)",newPath->address().toString(tmp),peer.address().toInt(),packetId,newPath->localSocket(),networkId);
  104. std::pair<Address,Trace::Level> byn;
  105. if (networkId) { Mutex::Lock l(_byNet_m); _byNet.get(networkId,byn); }
  106. if ((_globalTarget)||(byn.first)) {
  107. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  108. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PEER_LEARNED_NEW_PATH_S);
  109. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  110. if (networkId)
  111. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,networkId);
  112. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,peer.address());
  113. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,newPath->address().toString(tmp));
  114. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,newPath->localSocket());
  115. if (_globalTarget)
  116. _send(tPtr,d,_globalTarget);
  117. if (byn.first)
  118. _send(tPtr,d,byn.first);
  119. }
  120. }
  121. void Trace::peerRedirected(void *const tPtr,const uint64_t networkId,Peer &peer,const SharedPtr<Path> &newPath)
  122. {
  123. char tmp[128];
  124. if (!newPath) return; // sanity check
  125. ZT_LOCAL_TRACE(tPtr,RR,"explicit redirect from %.10llx to path %s",peer.address().toInt(),newPath->address().toString(tmp));
  126. std::pair<Address,Trace::Level> byn;
  127. if (networkId) { Mutex::Lock l(_byNet_m); _byNet.get(networkId,byn); }
  128. if ((_globalTarget)||(byn.first)) {
  129. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  130. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PEER_REDIRECTED_S);
  131. if (networkId)
  132. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,networkId);
  133. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,peer.address());
  134. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,newPath->address().toString(tmp));
  135. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,newPath->localSocket());
  136. if (_globalTarget)
  137. _send(tPtr,d,_globalTarget);
  138. if (byn.first)
  139. _send(tPtr,d,byn.first);
  140. }
  141. }
  142. void Trace::outgoingNetworkFrameDropped(void *const tPtr,const SharedPtr<Network> &network,const MAC &sourceMac,const MAC &destMac,const unsigned int etherType,const unsigned int vlanId,const unsigned int frameLen,const char *reason)
  143. {
  144. #ifdef ZT_TRACE
  145. char tmp[128],tmp2[128];
  146. #endif
  147. if (!network) return; // sanity check
  148. ZT_LOCAL_TRACE(tPtr,RR,"%.16llx DROP frame %s -> %s etherType %.4x size %u (%s)",network->id(),sourceMac.toString(tmp),destMac.toString(tmp2),etherType,frameLen,(reason) ? reason : "unknown reason");
  149. std::pair<Address,Trace::Level> byn;
  150. { Mutex::Lock l(_byNet_m); _byNet.get(network->id(),byn); }
  151. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE)) ) {
  152. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  153. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__OUTGOING_NETWORK_FRAME_DROPPED_S);
  154. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network->id());
  155. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_MAC,sourceMac.toInt());
  156. d.add(ZT_REMOTE_TRACE_FIELD__DEST_MAC,destMac.toInt());
  157. d.add(ZT_REMOTE_TRACE_FIELD__ETHERTYPE,(uint64_t)etherType);
  158. d.add(ZT_REMOTE_TRACE_FIELD__VLAN_ID,(uint64_t)vlanId);
  159. d.add(ZT_REMOTE_TRACE_FIELD__FRAME_LENGTH,(uint64_t)frameLen);
  160. if (reason)
  161. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  162. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE))
  163. _send(tPtr,d,_globalTarget);
  164. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE))
  165. _send(tPtr,d,byn.first);
  166. }
  167. }
  168. void Trace::incomingNetworkAccessDenied(void *const tPtr,const SharedPtr<Network> &network,const SharedPtr<Path> &path,const uint64_t packetId,const unsigned int packetLength,const Address &source,const Packet::Verb verb,bool credentialsRequested)
  169. {
  170. char tmp[128];
  171. if (!network) return; // sanity check
  172. ZT_LOCAL_TRACE(tPtr,RR,"%.16llx DENIED packet from %.10llx(%s) verb %d size %u%s",network->id(),source.toInt(),(path) ? (path->address().toString(tmp)) : "???",(int)verb,packetLength,credentialsRequested ? " (credentials requested)" : " (credentials not requested)");
  173. std::pair<Address,Trace::Level> byn;
  174. { Mutex::Lock l(_byNet_m); _byNet.get(network->id(),byn); }
  175. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE)) ) {
  176. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  177. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__INCOMING_NETWORK_ACCESS_DENIED_S);
  178. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  179. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  180. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  181. if (path) {
  182. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  183. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  184. }
  185. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network->id());
  186. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE))
  187. _send(tPtr,d,_globalTarget);
  188. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE))
  189. _send(tPtr,d,byn.first);
  190. }
  191. }
  192. void Trace::incomingNetworkFrameDropped(void *const tPtr,const SharedPtr<Network> &network,const SharedPtr<Path> &path,const uint64_t packetId,const unsigned int packetLength,const Address &source,const Packet::Verb verb,const MAC &sourceMac,const MAC &destMac,const char *reason)
  193. {
  194. char tmp[128];
  195. if (!network) return; // sanity check
  196. ZT_LOCAL_TRACE(tPtr,RR,"%.16llx DROPPED frame from %.10llx(%s) verb %d size %u",network->id(),source.toInt(),(path) ? (path->address().toString(tmp)) : "???",(int)verb,packetLength);
  197. std::pair<Address,Trace::Level> byn;
  198. { Mutex::Lock l(_byNet_m); _byNet.get(network->id(),byn); }
  199. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE)) ) {
  200. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  201. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__INCOMING_NETWORK_FRAME_DROPPED_S);
  202. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  203. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  204. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  205. if (path) {
  206. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  207. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  208. }
  209. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network->id());
  210. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_MAC,sourceMac.toInt());
  211. d.add(ZT_REMOTE_TRACE_FIELD__DEST_MAC,destMac.toInt());
  212. if (reason)
  213. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  214. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_VERBOSE))
  215. _send(tPtr,d,_globalTarget);
  216. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_VERBOSE))
  217. _send(tPtr,d,byn.first);
  218. }
  219. }
  220. void Trace::incomingPacketMessageAuthenticationFailure(void *const tPtr,const SharedPtr<Path> &path,const uint64_t packetId,const Address &source,const unsigned int hops,const char *reason)
  221. {
  222. char tmp[128];
  223. ZT_LOCAL_TRACE(tPtr,RR,"MAC failed for packet %.16llx from %.10llx(%s)",packetId,source.toInt(),(path) ? path->address().toString(tmp) : "???");
  224. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  225. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  226. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PACKET_MAC_FAILURE_S);
  227. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  228. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_HOPS,(uint64_t)hops);
  229. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  230. if (path) {
  231. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  232. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  233. }
  234. if (reason)
  235. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  236. _send(tPtr,d,_globalTarget);
  237. }
  238. }
  239. void Trace::incomingPacketInvalid(void *const tPtr,const SharedPtr<Path> &path,const uint64_t packetId,const Address &source,const unsigned int hops,const Packet::Verb verb,const char *reason)
  240. {
  241. char tmp[128];
  242. ZT_LOCAL_TRACE(tPtr,RR,"INVALID packet %.16llx from %.10llx(%s) (%s)",packetId,source.toInt(),(path) ? path->address().toString(tmp) : "???",(reason) ? reason : "unknown reason");
  243. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  244. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  245. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PACKET_INVALID_S);
  246. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  247. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_VERB,(uint64_t)verb);
  248. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  249. if (path) {
  250. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  251. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  252. }
  253. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_HOPS,(uint64_t)hops);
  254. if (reason)
  255. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  256. _send(tPtr,d,_globalTarget);
  257. }
  258. }
  259. void Trace::incomingPacketDroppedHELLO(void *const tPtr,const SharedPtr<Path> &path,const uint64_t packetId,const Address &source,const char *reason)
  260. {
  261. char tmp[128];
  262. ZT_LOCAL_TRACE(tPtr,RR,"DROPPED HELLO from %.10llx(%s) (%s)",source.toInt(),(path) ? path->address().toString(tmp) : "???",(reason) ? reason : "???");
  263. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  264. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  265. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__PACKET_INVALID_S);
  266. d.add(ZT_REMOTE_TRACE_FIELD__PACKET_ID,packetId);
  267. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_ZTADDR,source);
  268. if (path) {
  269. d.add(ZT_REMOTE_TRACE_FIELD__REMOTE_PHYADDR,path->address().toString(tmp));
  270. d.add(ZT_REMOTE_TRACE_FIELD__LOCAL_SOCKET,path->localSocket());
  271. }
  272. if (reason)
  273. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  274. _send(tPtr,d,_globalTarget);
  275. }
  276. }
  277. void Trace::networkConfigRequestSent(void *const tPtr,const Network &network,const Address &controller)
  278. {
  279. ZT_LOCAL_TRACE(tPtr,RR,"requesting configuration for network %.16llx",network.id());
  280. if ((_globalTarget)&&((int)_globalLevel >= Trace::LEVEL_DEBUG)) {
  281. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  282. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__NETWORK_CONFIG_REQUEST_SENT_S);
  283. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network.id());
  284. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_CONTROLLER_ID,controller);
  285. _send(tPtr,d,_globalTarget);
  286. }
  287. }
  288. void Trace::networkFilter(
  289. void *const tPtr,
  290. const Network &network,
  291. const RuleResultLog &primaryRuleSetLog,
  292. const RuleResultLog *const matchingCapabilityRuleSetLog,
  293. const Capability *const matchingCapability,
  294. const Address &ztSource,
  295. const Address &ztDest,
  296. const MAC &macSource,
  297. const MAC &macDest,
  298. const uint8_t *const frameData,
  299. const unsigned int frameLen,
  300. const unsigned int etherType,
  301. const unsigned int vlanId,
  302. const bool noTee,
  303. const bool inbound,
  304. const int accept)
  305. {
  306. std::pair<Address,Trace::Level> byn;
  307. { Mutex::Lock l(_byNet_m); _byNet.get(network.id(),byn); }
  308. if ( ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_RULES)) || ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_RULES)) ) {
  309. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  310. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__NETWORK_FILTER_TRACE_S);
  311. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,network.id());
  312. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_ZTADDR,ztSource);
  313. d.add(ZT_REMOTE_TRACE_FIELD__DEST_ZTADDR,ztDest);
  314. d.add(ZT_REMOTE_TRACE_FIELD__SOURCE_MAC,macSource.toInt());
  315. d.add(ZT_REMOTE_TRACE_FIELD__DEST_MAC,macDest.toInt());
  316. d.add(ZT_REMOTE_TRACE_FIELD__ETHERTYPE,(uint64_t)etherType);
  317. d.add(ZT_REMOTE_TRACE_FIELD__VLAN_ID,(uint64_t)vlanId);
  318. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_FLAG_NOTEE,noTee ? "1" : "0");
  319. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_FLAG_INBOUND,inbound ? "1" : "0");
  320. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_RESULT,(int64_t)accept);
  321. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_BASE_RULE_LOG,(const char *)primaryRuleSetLog.data(),(int)primaryRuleSetLog.sizeBytes());
  322. if (matchingCapabilityRuleSetLog)
  323. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_CAP_RULE_LOG,(const char *)matchingCapabilityRuleSetLog->data(),(int)matchingCapabilityRuleSetLog->sizeBytes());
  324. if (matchingCapability)
  325. d.add(ZT_REMOTE_TRACE_FIELD__FILTER_CAP_ID,(uint64_t)matchingCapability->id());
  326. d.add(ZT_REMOTE_TRACE_FIELD__FRAME_LENGTH,(uint64_t)frameLen);
  327. if (frameLen > 0)
  328. d.add(ZT_REMOTE_TRACE_FIELD__FRAME_DATA,(const char *)frameData,(frameLen > 256) ? (int)256 : (int)frameLen);
  329. if ((_globalTarget)&&((int)_globalLevel >= (int)Trace::LEVEL_RULES))
  330. _send(tPtr,d,_globalTarget);
  331. if ((byn.first)&&((int)byn.second >= (int)Trace::LEVEL_RULES))
  332. _send(tPtr,d,byn.first);
  333. }
  334. }
  335. void Trace::credentialRejected(void *const tPtr,const CertificateOfMembership &c,const char *reason)
  336. {
  337. std::pair<Address,Trace::Level> byn;
  338. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  339. if ((_globalTarget)||(byn.first)) {
  340. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  341. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  342. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  343. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  344. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  345. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  346. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  347. if (reason)
  348. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  349. if (_globalTarget)
  350. _send(tPtr,d,_globalTarget);
  351. if (byn.first)
  352. _send(tPtr,d,byn.first);
  353. }
  354. }
  355. void Trace::credentialRejected(void *const tPtr,const CertificateOfOwnership &c,const char *reason)
  356. {
  357. std::pair<Address,Trace::Level> byn;
  358. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  359. if ((_globalTarget)||(byn.first)) {
  360. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  361. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  362. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  363. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  364. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  365. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  366. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  367. if (reason)
  368. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  369. if (_globalTarget)
  370. _send(tPtr,d,_globalTarget);
  371. if (byn.first)
  372. _send(tPtr,d,byn.first);
  373. }
  374. }
  375. void Trace::credentialRejected(void *const tPtr,const Capability &c,const char *reason)
  376. {
  377. std::pair<Address,Trace::Level> byn;
  378. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  379. if ((_globalTarget)||(byn.first)) {
  380. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  381. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  382. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  383. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  384. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  385. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  386. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  387. if (reason)
  388. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  389. if (_globalTarget)
  390. _send(tPtr,d,_globalTarget);
  391. if (byn.first)
  392. _send(tPtr,d,byn.first);
  393. }
  394. }
  395. void Trace::credentialRejected(void *const tPtr,const Tag &c,const char *reason)
  396. {
  397. std::pair<Address,Trace::Level> byn;
  398. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  399. if ((_globalTarget)||(byn.first)) {
  400. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  401. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  402. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  403. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  404. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  405. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TIMESTAMP,c.timestamp());
  406. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ISSUED_TO,c.issuedTo());
  407. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_INFO,(uint64_t)c.value());
  408. if (reason)
  409. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  410. if (_globalTarget)
  411. _send(tPtr,d,_globalTarget);
  412. if (byn.first)
  413. _send(tPtr,d,byn.first);
  414. }
  415. }
  416. void Trace::credentialRejected(void *const tPtr,const Revocation &c,const char *reason)
  417. {
  418. std::pair<Address,Trace::Level> byn;
  419. if (c.networkId()) { Mutex::Lock l(_byNet_m); _byNet.get(c.networkId(),byn); }
  420. if ((_globalTarget)||(byn.first)) {
  421. Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> d;
  422. d.add(ZT_REMOTE_TRACE_FIELD__EVENT,ZT_REMOTE_TRACE_EVENT__CREDENTIAL_REJECTED_S);
  423. d.add(ZT_REMOTE_TRACE_FIELD__NETWORK_ID,c.networkId());
  424. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_TYPE,(uint64_t)c.credentialType());
  425. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_ID,(uint64_t)c.id());
  426. d.add(ZT_REMOTE_TRACE_FIELD__CREDENTIAL_REVOCATION_TARGET,c.target());
  427. if (reason)
  428. d.add(ZT_REMOTE_TRACE_FIELD__REASON,reason);
  429. if (_globalTarget)
  430. _send(tPtr,d,_globalTarget);
  431. if (byn.first)
  432. _send(tPtr,d,byn.first);
  433. }
  434. }
  435. void Trace::updateMemoizedSettings()
  436. {
  437. _globalTarget = RR->node->remoteTraceTarget();
  438. _globalLevel = RR->node->remoteTraceLevel();
  439. const std::vector< SharedPtr<Network> > nws(RR->node->allNetworks());
  440. {
  441. Mutex::Lock l(_byNet_m);
  442. _byNet.clear();
  443. for(std::vector< SharedPtr<Network> >::const_iterator n(nws.begin());n!=nws.end();++n) {
  444. const Address dest((*n)->config().remoteTraceTarget);
  445. if (dest) {
  446. std::pair<Address,Trace::Level> &m = _byNet[(*n)->id()];
  447. m.first = dest;
  448. m.second = (*n)->config().remoteTraceLevel;
  449. }
  450. }
  451. }
  452. }
  453. void Trace::_send(void *const tPtr,const Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> &d,const Address &dest)
  454. {
  455. Packet outp(dest,RR->identity.address(),Packet::VERB_REMOTE_TRACE);
  456. outp.appendCString(d.data());
  457. outp.compress();
  458. RR->sw->send(tPtr,outp,true);
  459. }
  460. void Trace::_spamToAllNetworks(void *const tPtr,const Dictionary<ZT_MAX_REMOTE_TRACE_SIZE> &d,const Level level)
  461. {
  462. Mutex::Lock l(_byNet_m);
  463. Hashtable< uint64_t,std::pair< Address,Trace::Level > >::Iterator i(_byNet);
  464. uint64_t *k = (uint64_t *)0;
  465. std::pair<Address,Trace::Level> *v = (std::pair<Address,Trace::Level> *)0;
  466. while (i.next(k,v)) {
  467. if ((v)&&(v->first)&&((int)v->second >= (int)level))
  468. _send(tPtr,d,v->first);
  469. }
  470. }
  471. } // namespace ZeroTier