2007-12-17 23:44:11 +01:00
|
|
|
/* Copyright (c) 2007, The Tor Project, Inc. */
|
|
|
|
/* See LICENSE for licensing information */
|
|
|
|
/* $Id: /tor/trunk/src/or/networkstatus.c 15493 2007-12-16T18:33:25.055570Z nickm $ */
|
|
|
|
const char geoip_c_id[] =
|
|
|
|
"$Id: /tor/trunk/src/or/networkstatus.c 15493 2007-12-16T18:33:25.055570Z nickm $";
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/**
|
|
|
|
* \file geoip.c
|
|
|
|
* \brief Functions related to maintaining an IP-to-country database and to
|
|
|
|
* summarizing client connections by country.
|
|
|
|
*/
|
|
|
|
|
2007-12-17 23:44:11 +01:00
|
|
|
#define GEOIP_PRIVATE
|
|
|
|
#include "or.h"
|
|
|
|
#include "ht.h"
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
static void clear_geoip_db(void);
|
2007-12-17 23:44:11 +01:00
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** An entry from the GeoIP file: maps an IP range to a country. */
|
2007-12-17 23:44:11 +01:00
|
|
|
typedef struct geoip_entry_t {
|
2007-12-18 22:27:08 +01:00
|
|
|
uint32_t ip_low; /**< The lowest IP in the range, in host order */
|
|
|
|
uint32_t ip_high; /**< The highest IP in the range, in host order */
|
|
|
|
int country; /**< An index into geoip_countries */
|
2007-12-17 23:44:11 +01:00
|
|
|
} geoip_entry_t;
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** A list of lowercased two-letter country codes. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static smartlist_t *geoip_countries = NULL;
|
2007-12-18 22:27:08 +01:00
|
|
|
/** A map from lowercased country codes to their position in geoip_countries.
|
|
|
|
* The index is encoded in the pointer, and 1 is added so that NULL can mean
|
|
|
|
* not found. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static strmap_t *country_idxplus1_by_lc_code = NULL;
|
2007-12-18 22:27:08 +01:00
|
|
|
/** A list of all known geoip_entry_t, sorted by ip_low. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static smartlist_t *geoip_entries = NULL;
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Add an entry to the GeoIP table, mapping all IPs between <b>low</b> and
|
|
|
|
* <b>high</b>, inclusive, to the 2-letter country code <b>country</b>.
|
|
|
|
*/
|
|
|
|
static void
|
2007-12-17 23:44:11 +01:00
|
|
|
geoip_add_entry(uint32_t low, uint32_t high, const char *country)
|
|
|
|
{
|
|
|
|
uintptr_t idx;
|
|
|
|
geoip_entry_t *ent;
|
2007-12-18 22:27:08 +01:00
|
|
|
void *_idxplus1;
|
|
|
|
|
|
|
|
if (high < low)
|
|
|
|
return;
|
|
|
|
|
|
|
|
_idxplus1 = strmap_get_lc(country_idxplus1_by_lc_code, country);
|
2007-12-17 23:44:11 +01:00
|
|
|
|
|
|
|
if (!_idxplus1) {
|
|
|
|
char *c = tor_strdup(country);
|
|
|
|
tor_strlower(c);
|
|
|
|
smartlist_add(geoip_countries, c);
|
2007-12-17 23:44:18 +01:00
|
|
|
idx = smartlist_len(geoip_countries) - 1;
|
2007-12-17 23:44:11 +01:00
|
|
|
strmap_set_lc(country_idxplus1_by_lc_code, country, (void*)(idx+1));
|
|
|
|
} else {
|
|
|
|
idx = ((uintptr_t)_idxplus1)-1;
|
|
|
|
}
|
2007-12-17 23:44:18 +01:00
|
|
|
tor_assert(!strcasecmp(smartlist_get(geoip_countries, idx), country));
|
2007-12-17 23:44:11 +01:00
|
|
|
ent = tor_malloc_zero(sizeof(geoip_entry_t));
|
|
|
|
ent->ip_low = low;
|
|
|
|
ent->ip_high = high;
|
|
|
|
ent->country = idx;
|
|
|
|
smartlist_add(geoip_entries, ent);
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Add an entry to the GeoIP table, parsing it from <b>line</b>. The
|
|
|
|
* format is as for geoip_load_file. */
|
|
|
|
/*private*/ int
|
|
|
|
geoip_parse_entry(const char *line)
|
|
|
|
{
|
|
|
|
unsigned int low, high;
|
|
|
|
char b[3];
|
|
|
|
if (!geoip_countries) {
|
|
|
|
geoip_countries = smartlist_create();
|
|
|
|
geoip_entries = smartlist_create();
|
|
|
|
country_idxplus1_by_lc_code = strmap_new();
|
|
|
|
}
|
|
|
|
if (sscanf(line,"%u,%u,%2s", &low, &high, b) == 3) {
|
|
|
|
geoip_add_entry(low, high, b);
|
|
|
|
return 0;
|
|
|
|
} else if (sscanf(line,"\"%u\",\"%u\",\"%2s\",", &low, &high, b) == 3) {
|
|
|
|
geoip_add_entry(low, high, b);
|
|
|
|
return 0;
|
|
|
|
} else {
|
|
|
|
log_warn(LD_GENERAL, "Unable to parse line from GEOIP file: %s",
|
|
|
|
escaped(line));
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/** Sorting helper: return -1, 1, or 0 based on comparison of two
|
|
|
|
* geoip_entry_t */
|
2007-12-17 23:44:11 +01:00
|
|
|
static int
|
|
|
|
_geoip_compare_entries(const void **_a, const void **_b)
|
|
|
|
{
|
|
|
|
const geoip_entry_t *a = *_a, *b = *_b;
|
|
|
|
if (a->ip_low < b->ip_low)
|
|
|
|
return -1;
|
|
|
|
else if (a->ip_low > b->ip_low)
|
|
|
|
return 1;
|
|
|
|
else
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** bsearch helper: return -1, 1, or 0 based on comparison of an IP (a pointer
|
|
|
|
* to a uint32_t in host order) to a geoip_entry_t */
|
2007-12-17 23:44:11 +01:00
|
|
|
static int
|
|
|
|
_geoip_compare_key_to_entry(const void *_key, const void **_member)
|
|
|
|
{
|
|
|
|
const uint32_t addr = *(uint32_t *)_key;
|
|
|
|
const geoip_entry_t *entry = *_member;
|
|
|
|
if (addr < entry->ip_low)
|
|
|
|
return -1;
|
|
|
|
else if (addr > entry->ip_high)
|
|
|
|
return 1;
|
|
|
|
else
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Clear the GeoIP database and reload it from the file
|
|
|
|
* <b>filename</b>. Return 0 on success, -1 on failure.
|
|
|
|
*
|
|
|
|
* Recognized line formats are:
|
|
|
|
* INTIPLOW,INTIPHIGH,CC
|
|
|
|
* and
|
|
|
|
* "INTIPLOW","INTIPHIGH","CC","CC3","COUNTRY NAME"
|
|
|
|
* where INTIPLOW and INTIPHIGH are IPv4 addresses encoded as 4-byte unsigned
|
|
|
|
* integers, and CC is a country code.
|
|
|
|
*/
|
2007-12-17 23:44:11 +01:00
|
|
|
int
|
|
|
|
geoip_load_file(const char *filename)
|
|
|
|
{
|
|
|
|
FILE *f;
|
2007-12-18 22:27:08 +01:00
|
|
|
clear_geoip_db();
|
2007-12-17 23:44:11 +01:00
|
|
|
if (!(f = fopen(filename, "r"))) {
|
|
|
|
log_warn(LD_GENERAL, "Failed to open GEOIP file %s.", filename);
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
geoip_countries = smartlist_create();
|
|
|
|
geoip_entries = smartlist_create();
|
|
|
|
country_idxplus1_by_lc_code = strmap_new();
|
2007-12-17 23:44:18 +01:00
|
|
|
log_info(LD_GENERAL, "Parsing GEOIP file.");
|
2007-12-17 23:44:11 +01:00
|
|
|
while (!feof(f)) {
|
2007-12-17 23:44:16 +01:00
|
|
|
char buf[512];
|
|
|
|
if (fgets(buf, sizeof(buf), f) == NULL)
|
|
|
|
break;
|
2007-12-17 23:44:18 +01:00
|
|
|
/* XXXX020 track full country name. */
|
2007-12-18 22:27:08 +01:00
|
|
|
geoip_parse_entry(buf);
|
2007-12-17 23:44:11 +01:00
|
|
|
}
|
2007-12-17 23:44:18 +01:00
|
|
|
/*XXXX020 abort and return -1 if no entries/illformed?*/
|
2007-12-17 23:44:11 +01:00
|
|
|
fclose(f);
|
|
|
|
|
|
|
|
smartlist_sort(geoip_entries, _geoip_compare_entries);
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Given an IP address in host order, return a number representing the
|
|
|
|
* country to which that address belongs, or -1 for unknown. The return value
|
|
|
|
* will always be less than geoip_get_n_countries(). To decode it,
|
|
|
|
* call geoip_get_country_name().
|
|
|
|
*/
|
2007-12-17 23:44:11 +01:00
|
|
|
int
|
|
|
|
geoip_get_country_by_ip(uint32_t ipaddr)
|
|
|
|
{
|
|
|
|
geoip_entry_t *ent;
|
|
|
|
if (!geoip_entries)
|
|
|
|
return -1;
|
|
|
|
ent = smartlist_bsearch(geoip_entries, &ipaddr, _geoip_compare_key_to_entry);
|
|
|
|
return ent ? ent->country : -1;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Return the number of countries recognized by the GEOIP database. */
|
2007-12-17 23:44:11 +01:00
|
|
|
int
|
|
|
|
geoip_get_n_countries(void)
|
|
|
|
{
|
|
|
|
return smartlist_len(geoip_countries);
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Return the two-letter country code associated with the number <b>num</b>,
|
|
|
|
* or "??" for an unknown value. */
|
2007-12-17 23:44:11 +01:00
|
|
|
const char *
|
|
|
|
geoip_get_country_name(int num)
|
|
|
|
{
|
|
|
|
if (geoip_countries && num >= 0 && num < smartlist_len(geoip_countries))
|
|
|
|
return smartlist_get(geoip_countries, num);
|
|
|
|
else
|
|
|
|
return "??";
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Return true iff we have loaded a GeoIP database.*/
|
2007-12-17 23:44:11 +01:00
|
|
|
int
|
|
|
|
geoip_is_loaded(void)
|
|
|
|
{
|
|
|
|
return geoip_countries != NULL && geoip_entries != NULL;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Entry in a map from IP address to the last time we've seen an incoming
|
|
|
|
* connection from that IP address. Used by bridges only, to track which
|
|
|
|
* countries have them blocked. */
|
2007-12-17 23:44:11 +01:00
|
|
|
typedef struct clientmap_entry_t {
|
|
|
|
HT_ENTRY(clientmap_entry_t) node;
|
|
|
|
uint32_t ipaddr;
|
|
|
|
time_t last_seen;
|
|
|
|
} clientmap_entry_t;
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Map from client IP address to last time seen. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static HT_HEAD(clientmap, clientmap_entry_t) client_history =
|
|
|
|
HT_INITIALIZER();
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Time at which we started tracking client history. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static time_t client_history_starts = 0;
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Hashtable helper: compute a hash of a clientmap_entry_t. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static INLINE unsigned
|
|
|
|
clientmap_entry_hash(const clientmap_entry_t *a)
|
|
|
|
{
|
|
|
|
return ht_improve_hash((unsigned) a->ipaddr);
|
|
|
|
}
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Hashtable helper: compare two clientmap_entry_t values for equality. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static INLINE int
|
|
|
|
clientmap_entries_eq(const clientmap_entry_t *a, const clientmap_entry_t *b)
|
|
|
|
{
|
|
|
|
return a->ipaddr == b->ipaddr;
|
|
|
|
}
|
|
|
|
|
|
|
|
HT_PROTOTYPE(clientmap, clientmap_entry_t, node, clientmap_entry_hash,
|
|
|
|
clientmap_entries_eq);
|
|
|
|
HT_GENERATE(clientmap, clientmap_entry_t, node, clientmap_entry_hash,
|
|
|
|
clientmap_entries_eq, 0.6, malloc, realloc, free);
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Note that we've seen a client connect from the IP <b>addr</b> (host order)
|
|
|
|
* at time <b>now</b>. Ignored by all but bridges. */
|
2007-12-17 23:44:11 +01:00
|
|
|
void
|
|
|
|
geoip_note_client_seen(uint32_t addr, time_t now)
|
|
|
|
{
|
|
|
|
or_options_t *options = get_options();
|
|
|
|
clientmap_entry_t lookup, *ent;
|
|
|
|
if (!(options->BridgeRelay && options->BridgeRecordUsageByCountry))
|
|
|
|
return;
|
|
|
|
lookup.ipaddr = addr;
|
|
|
|
ent = HT_FIND(clientmap, &client_history, &lookup);
|
|
|
|
if (ent) {
|
|
|
|
ent->last_seen = now;
|
|
|
|
} else {
|
|
|
|
ent = tor_malloc_zero(sizeof(clientmap_entry_t));
|
|
|
|
ent->ipaddr = addr;
|
|
|
|
ent->last_seen = now;
|
|
|
|
HT_INSERT(clientmap, &client_history, ent);
|
|
|
|
}
|
|
|
|
if (!client_history_starts)
|
|
|
|
client_history_starts = now;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** HT_FOREACH helper: remove a clientmap_entry_t from the hashtable if it's
|
|
|
|
* older than a certain time. */
|
2007-12-17 23:44:11 +01:00
|
|
|
static int
|
|
|
|
_remove_old_client_helper(struct clientmap_entry_t *ent, void *_cutoff)
|
|
|
|
{
|
|
|
|
time_t cutoff = *(time_t*)_cutoff;
|
|
|
|
if (ent->last_seen < cutoff) {
|
|
|
|
tor_free(ent);
|
|
|
|
return 1;
|
|
|
|
} else {
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Forget about all clients that haven't connected since <b>cutoff</b>. */
|
2007-12-17 23:44:11 +01:00
|
|
|
void
|
|
|
|
geoip_remove_old_clients(time_t cutoff)
|
|
|
|
{
|
|
|
|
clientmap_HT_FOREACH_FN(&client_history,
|
|
|
|
_remove_old_client_helper,
|
|
|
|
&cutoff);
|
|
|
|
if (client_history_starts < cutoff)
|
|
|
|
client_history_starts = cutoff;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Do not mention any country from which fewer than this number of IPs have
|
|
|
|
* connected. This avoids reporting information that could deanonymize
|
|
|
|
* users. */
|
2007-12-17 23:44:11 +01:00
|
|
|
#define MIN_IPS_TO_NOTE_COUNTRY 8
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Do not report any geoip data at all if we have fewer than this number of
|
|
|
|
* IPs to report about. */
|
2007-12-17 23:44:11 +01:00
|
|
|
#define MIN_IPS_TO_NOTE_ANYTHING 16
|
2007-12-18 22:27:08 +01:00
|
|
|
/** When reporting geoip data about countries, round down to the nearest
|
|
|
|
* multiple of this value. */
|
2007-12-17 23:44:11 +01:00
|
|
|
#define IP_GRANULARITY 8
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Return the time at which we started recording geoip data. */
|
2007-12-17 23:44:16 +01:00
|
|
|
time_t
|
|
|
|
geoip_get_history_start(void)
|
|
|
|
{
|
|
|
|
return client_history_starts;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Return a newly allocated comma-separated string containing entries for all
|
|
|
|
* the countries from which we've seen enough clients connect. The entry
|
|
|
|
* format is cc=num where num is the number of IPs we've seen connecting from
|
|
|
|
* that country, and cc is a lowercased country code. Returns NULL if we don't
|
|
|
|
* want to export geoip data yet. */
|
2007-12-17 23:44:11 +01:00
|
|
|
char *
|
|
|
|
geoip_get_client_history(time_t now)
|
|
|
|
{
|
|
|
|
char *result = NULL;
|
|
|
|
if (!geoip_is_loaded())
|
|
|
|
return NULL;
|
|
|
|
if (client_history_starts < (now - 12*60*60)) {
|
|
|
|
char buf[32];
|
|
|
|
smartlist_t *chunks = NULL;
|
|
|
|
int n_countries = geoip_get_n_countries();
|
|
|
|
int i;
|
|
|
|
clientmap_entry_t **ent;
|
|
|
|
unsigned *counts = tor_malloc_zero(sizeof(unsigned)*n_countries);
|
|
|
|
unsigned total = 0;
|
|
|
|
HT_FOREACH(ent, clientmap, &client_history) {
|
|
|
|
int country = geoip_get_country_by_ip((*ent)->ipaddr);
|
|
|
|
if (country < 0)
|
|
|
|
continue;
|
|
|
|
tor_assert(0 <= country && country < n_countries);
|
|
|
|
++counts[country];
|
|
|
|
++total;
|
|
|
|
}
|
|
|
|
if (total < MIN_IPS_TO_NOTE_ANYTHING)
|
|
|
|
goto done;
|
|
|
|
chunks = smartlist_create();
|
|
|
|
for (i = 0; i < n_countries; ++i) {
|
|
|
|
unsigned c = counts[i];
|
|
|
|
const char *countrycode;
|
|
|
|
if (c >= MIN_IPS_TO_NOTE_COUNTRY) {
|
|
|
|
c -= c % IP_GRANULARITY;
|
|
|
|
countrycode = geoip_get_country_name(i);
|
|
|
|
tor_snprintf(buf, sizeof(buf), "%s=%u", countrycode, c);
|
|
|
|
smartlist_add(chunks, tor_strdup(buf));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
result = smartlist_join_strings(chunks, ",", 0, NULL);
|
|
|
|
done:
|
|
|
|
tor_free(counts);
|
|
|
|
if (chunks) {
|
|
|
|
SMARTLIST_FOREACH(chunks, char *, c, tor_free(c));
|
|
|
|
smartlist_free(chunks);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return result;
|
|
|
|
}
|
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Helper used to implement GETINFO ip-to-country/... controller command. */
|
2007-12-17 23:44:18 +01:00
|
|
|
int
|
|
|
|
getinfo_helper_geoip(control_connection_t *control_conn,
|
|
|
|
const char *question, char **answer)
|
|
|
|
{
|
|
|
|
(void)control_conn;
|
|
|
|
if (geoip_is_loaded() && !strcmpstart(question, "ip-to-country/")) {
|
|
|
|
int c;
|
|
|
|
uint32_t ip;
|
|
|
|
struct in_addr in;
|
|
|
|
question += strlen("ip-to-country/");
|
|
|
|
if (tor_inet_aton(question, &in) != 0) {
|
|
|
|
ip = ntohl(in.s_addr);
|
|
|
|
c = geoip_get_country_by_ip(ip);
|
|
|
|
*answer = tor_strdup(geoip_get_country_name(c));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
2007-12-17 23:44:11 +01:00
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Release all storage held by the GeoIP database. */
|
|
|
|
static void
|
|
|
|
clear_geoip_db(void)
|
2007-12-17 23:44:11 +01:00
|
|
|
{
|
|
|
|
if (geoip_countries) {
|
|
|
|
SMARTLIST_FOREACH(geoip_countries, char *, cp, tor_free(cp));
|
|
|
|
smartlist_free(geoip_countries);
|
|
|
|
}
|
|
|
|
if (country_idxplus1_by_lc_code)
|
|
|
|
strmap_free(country_idxplus1_by_lc_code, NULL);
|
|
|
|
if (geoip_entries) {
|
|
|
|
SMARTLIST_FOREACH(geoip_entries, geoip_entry_t *, ent, tor_free(ent));
|
|
|
|
smartlist_free(geoip_entries);
|
|
|
|
}
|
|
|
|
geoip_countries = NULL;
|
|
|
|
country_idxplus1_by_lc_code = NULL;
|
|
|
|
geoip_entries = NULL;
|
|
|
|
}
|
2007-12-17 23:44:18 +01:00
|
|
|
|
2007-12-18 22:27:08 +01:00
|
|
|
/** Release all storage held in this file. */
|
|
|
|
void
|
|
|
|
geoip_free_all(void)
|
|
|
|
{
|
|
|
|
clientmap_entry_t **ent, **next, *this;
|
|
|
|
for (ent = HT_START(clientmap, &client_history); ent != NULL; ent = next) {
|
|
|
|
this = *ent;
|
|
|
|
next = HT_NEXT_RMV(clientmap, &client_history, ent);
|
|
|
|
tor_free(this);
|
|
|
|
}
|
|
|
|
HT_CLEAR(clientmap, &client_history);
|
|
|
|
|
|
|
|
clear_geoip_db();
|
|
|
|
}
|
|
|
|
|