summaryrefslogtreecommitdiff
path: root/src/tools/tor-fw-helper
diff options
context:
space:
mode:
authorJacob Appelbaum <jacob@appelbaum.net>2010-04-16 17:45:12 -0700
committerNick Mathewson <nickm@torproject.org>2010-09-30 11:37:53 -0400
commit9cc76cf0053cad90d2ff55d24993d9a0ac4c0cdb (patch)
tree46bcd8f511653b52b5b7fe1348485e42b43b9fab /src/tools/tor-fw-helper
parent3ad43ef75f09a21c0c1fc6eb173f8d131c7d638c (diff)
downloadtor-9cc76cf0053cad90d2ff55d24993d9a0ac4c0cdb.tar.gz
tor-9cc76cf0053cad90d2ff55d24993d9a0ac4c0cdb.zip
First implementation of tor-fw-helper.
tor-fw-helper is a command-line tool to wrap and abstract various firewall port-forwarding tools. This commit matches the state of Jacob's tor-fw-helper branch as of 23 September 2010. (commit msg by Nick)
Diffstat (limited to 'src/tools/tor-fw-helper')
-rw-r--r--src/tools/tor-fw-helper/Makefile.am12
-rw-r--r--src/tools/tor-fw-helper/tor-fw-helper-natpmp.c142
-rw-r--r--src/tools/tor-fw-helper/tor-fw-helper-natpmp.h18
-rw-r--r--src/tools/tor-fw-helper/tor-fw-helper-upnp.c125
-rw-r--r--src/tools/tor-fw-helper/tor-fw-helper-upnp.h32
-rw-r--r--src/tools/tor-fw-helper/tor-fw-helper.c285
-rw-r--r--src/tools/tor-fw-helper/tor-fw-helper.h33
7 files changed, 647 insertions, 0 deletions
diff --git a/src/tools/tor-fw-helper/Makefile.am b/src/tools/tor-fw-helper/Makefile.am
new file mode 100644
index 0000000000..272da0060b
--- /dev/null
+++ b/src/tools/tor-fw-helper/Makefile.am
@@ -0,0 +1,12 @@
+if USE_FW_HELPER
+bin_PROGRAMS = tor-fw-helper
+else
+bin_PROGRAMS =
+endif
+
+tor_fw_helper_SOURCES = tor-fw-helper.c \
+ tor-fw-helper-natpmp.c tor-fw-helper-upnp.c
+tor_fw_helper_INCLUDES = tor-fw-helper.h tor-fw-helper-natpmp.h tor-fw-helper-upnp.h
+tor_fw_helper_LDFLAGS = @TOR_LDFLAGS_libnatpmp@ @TOR_LDFLAGS_libminiupnpc@
+tor_fw_helper_LDADD = -lnatpmp -lminiupnpc ../../common/libor.a @TOR_LIB_WS32@
+tor_fw_helper_CPPFLAGS = @TOR_CPPFLAGS_libnatpmp@ @TOR_CPPFLAGS_libminiupnpc@
diff --git a/src/tools/tor-fw-helper/tor-fw-helper-natpmp.c b/src/tools/tor-fw-helper/tor-fw-helper-natpmp.c
new file mode 100644
index 0000000000..ebcd9e61ad
--- /dev/null
+++ b/src/tools/tor-fw-helper/tor-fw-helper-natpmp.c
@@ -0,0 +1,142 @@
+/* Copyright (c) 2010, Jacob Appelbaum, Steven J. Murdoch.
+ * Copyright (c) 2010, The Tor Project, Inc. */
+/* See LICENSE for licensing information */
+
+#include <stdint.h>
+#include <stdio.h>
+#include <string.h>
+#include <errno.h>
+#include <arpa/inet.h>
+
+#include "tor-fw-helper.h"
+#include "tor-fw-helper-natpmp.h"
+
+int
+tor_natpmp_add_tcp_mapping(tor_fw_options_t *tor_fw_options)
+{
+ int r = 0;
+ int x = 0;
+ int sav_errno;
+ int protocol = NATPMP_PROTOCOL_TCP;
+ int lease = NATPMP_DEFAULT_LEASE;
+ natpmp_t natpmp;
+ natpmpresp_t response;
+
+ fd_set fds;
+ struct timeval timeout;
+
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: natpmp init...\n");
+ initnatpmp(&natpmp);
+
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: sending natpmp portmapping request...\n");
+ r = sendnewportmappingrequest(&natpmp, protocol,
+ tor_fw_options->internal_port,
+ tor_fw_options->external_port,
+ lease);
+ fprintf(stdout, "tor-fw-helper: NAT-PMP sendnewportmappingrequest returned"
+ " %d (%s)\n", r, r==12?"SUCCESS":"FAILED");
+
+ do {
+ FD_ZERO(&fds);
+ FD_SET(natpmp.s, &fds);
+ getnatpmprequesttimeout(&natpmp, &timeout);
+ select(FD_SETSIZE, &fds, NULL, NULL, &timeout);
+
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: attempting to readnatpmpreponseorretry...\n");
+ r = readnatpmpresponseorretry(&natpmp, &response);
+ sav_errno = errno;
+
+ if (r<0 && r!=NATPMP_TRYAGAIN)
+ {
+ fprintf(stderr, "E: readnatpmpresponseorretry failed %d\n", r);
+ fprintf(stderr, "E: errno=%d '%s'\n", sav_errno,
+ strerror(sav_errno));
+ }
+
+ } while ( r == NATPMP_TRYAGAIN );
+
+ if (r == NATPMP_SUCCESS) {
+ fprintf(stdout, "tor-fw-helper: NAT-PMP mapped public port %hu to"
+ " localport %hu liftime %u\n",
+ response.pnu.newportmapping.mappedpublicport,
+ response.pnu.newportmapping.privateport,
+ response.pnu.newportmapping.lifetime);
+ }
+
+ x = closenatpmp(&natpmp);
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: closing natpmp socket: %d\n", x);
+ return r;
+}
+
+int
+tor_natpmp_fetch_public_ip(tor_fw_options_t *tor_fw_options)
+{
+ int r = 0;
+ int x = 0;
+ int sav_errno;
+ natpmp_t natpmp;
+ natpmpresp_t response;
+ struct timeval timeout;
+ fd_set fds;
+
+ r = initnatpmp(&natpmp);
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: NAT-PMP init: %d\n", r);
+
+ r = sendpublicaddressrequest(&natpmp);
+ fprintf(stdout, "tor-fw-helper: NAT-PMP sendpublicaddressrequest returned"
+ " %d (%s)\n", r, r==2?"SUCCESS":"FAILED");
+
+ do {
+ FD_ZERO(&fds);
+ FD_SET(natpmp.s, &fds);
+ getnatpmprequesttimeout(&natpmp, &timeout);
+ select(FD_SETSIZE, &fds, NULL, NULL, &timeout);
+
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: NAT-PMP attempting to read reponse...\n");
+ r = readnatpmpresponseorretry(&natpmp, &response);
+ sav_errno = errno;
+
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: NAT-PMP readnatpmpresponseorretry returned"
+ " %d\n", r);
+
+ if ( r < 0 && r != NATPMP_TRYAGAIN)
+ {
+ fprintf(stderr, "E: NAT-PMP readnatpmpresponseorretry failed %d\n",
+ r);
+ fprintf(stderr, "E: NAT-PMP errno=%d '%s'\n", sav_errno,
+ strerror(sav_errno));
+ }
+
+ } while ( r == NATPMP_TRYAGAIN );
+
+ if (r != 0)
+ {
+ fprintf(stderr, "E: NAT-PMP It appears that something went wrong:"
+ " %d\n", r);
+ return r;
+ }
+
+ fprintf(stdout, "tor-fw-helper: ExternalIPAddress = %s\n",
+ inet_ntoa(response.pnu.publicaddress.addr));
+
+ x = closenatpmp(&natpmp);
+
+ if (tor_fw_options->verbose)
+ {
+ fprintf(stdout, "V: result = %u\n", r);
+ fprintf(stdout, "V: type = %u\n", response.type);
+ fprintf(stdout, "V: resultcode = %u\n", response.resultcode);
+ fprintf(stdout, "V: epoch = %u\n", response.epoch);
+ fprintf(stdout, "V: closing natpmp result: %d\n", r);
+ }
+
+ return r;
+}
+
diff --git a/src/tools/tor-fw-helper/tor-fw-helper-natpmp.h b/src/tools/tor-fw-helper/tor-fw-helper-natpmp.h
new file mode 100644
index 0000000000..8fc1765f9f
--- /dev/null
+++ b/src/tools/tor-fw-helper/tor-fw-helper-natpmp.h
@@ -0,0 +1,18 @@
+/* Copyright (c) 2010, Jacob Appelbaum, Steven J. Murdoch.
+ * Copyright (c) 2010, The Tor Project, Inc. */
+/* See LICENSE for licensing information */
+
+#ifndef _TOR_FW_HELPER_NATPMP_H
+#define _TOR_FW_HELPER_NATPMP_H
+
+#include <natpmp.h>
+
+#define NATPMP_DEFAULT_LEASE 3600
+#define NATPMP_SUCCESS 0
+
+int tor_natpmp_add_tcp_mapping(tor_fw_options_t *tor_fw_options);
+
+int tor_natpmp_fetch_public_ip(tor_fw_options_t *tor_fw_options);
+
+#endif
+
diff --git a/src/tools/tor-fw-helper/tor-fw-helper-upnp.c b/src/tools/tor-fw-helper/tor-fw-helper-upnp.c
new file mode 100644
index 0000000000..b471a6cd6f
--- /dev/null
+++ b/src/tools/tor-fw-helper/tor-fw-helper-upnp.c
@@ -0,0 +1,125 @@
+/* Copyright (c) 2010, Jacob Appelbaum, Steven J. Murdoch.
+ * Copyright (c) 2010, The Tor Project, Inc. */
+/* See LICENSE for licensing information */
+
+#include <stdint.h>
+#include <string.h>
+#include <stdio.h>
+
+#include "tor-fw-helper.h"
+#include "tor-fw-helper-upnp.h"
+
+#define UPNP_DISCOVER_TIMEOUT 2000
+/* Description of the port mapping in the UPnP table */
+#define UPNP_DESC "Tor relay"
+
+#define UPNP_ERR_SUCCESS 0
+#define UPNP_ERR_NODEVICESFOUND 1
+#define UPNP_ERR_NOIGDFOUND 2
+#define UPNP_ERR_ADDPORTMAPPING 3
+#define UPNP_ERR_GETPORTMAPPING 4
+#define UPNP_ERR_DELPORTMAPPING 5
+#define UPNP_ERR_GETEXTERNALIP 6
+#define UPNP_ERR_INVAL 7
+#define UPNP_ERR_OTHER 8
+#define UPNP_SUCCESS 1
+
+int
+tor_upnp_init(miniupnpc_state_t *state)
+{
+ struct UPNPDev *devlist;
+ int r;
+
+ memset(&(state->urls), 0, sizeof(struct UPNPUrls));
+ memset(&(state->data), 0, sizeof(struct IGDdatas));
+
+ devlist = upnpDiscover(UPNP_DISCOVER_TIMEOUT, NULL, NULL, 0);
+ if (NULL == devlist) {
+ fprintf(stderr, "E: upnpDiscover returned: NULL\n");
+ return UPNP_ERR_NODEVICESFOUND;
+ }
+
+ r = UPNP_GetValidIGD(devlist, &(state->urls), &(state->data),
+ state->lanaddr, UPNP_LANADDR_SZ);
+ fprintf(stdout, "tor-fw-helper: UPnP GetValidIGD returned: %d (%s)\n", r,
+ r==UPNP_SUCCESS?"SUCCESS":"FAILED");
+
+ freeUPNPDevlist(devlist);
+
+ if (r != 1 && r != 2)
+ return UPNP_ERR_NOIGDFOUND;
+
+ state->init = 1;
+ return UPNP_ERR_SUCCESS;
+}
+
+int
+tor_upnp_cleanup(miniupnpc_state_t *state)
+{
+ if (state->init)
+ FreeUPNPUrls(&(state->urls));
+ state->init = 0;
+
+ return UPNP_ERR_SUCCESS;
+}
+
+int
+tor_upnp_fetch_public_ip(miniupnpc_state_t *state)
+{
+ int r;
+ char externalIPAddress[16];
+
+ if (!state->init) {
+ r = tor_upnp_init(state);
+ if (r != UPNP_ERR_SUCCESS)
+ return r;
+ }
+
+ r = UPNP_GetExternalIPAddress(state->urls.controlURL,
+ state->data.first.servicetype,
+ externalIPAddress);
+
+ if (r != UPNPCOMMAND_SUCCESS)
+ goto err;
+
+ if (externalIPAddress[0]) {
+ fprintf(stdout, "tor-fw-helper: ExternalIPAddress = %s\n",
+ externalIPAddress); tor_upnp_cleanup(state);
+ return UPNP_ERR_SUCCESS;
+ } else
+ goto err;
+
+ err:
+ tor_upnp_cleanup(state);
+ return UPNP_ERR_GETEXTERNALIP;
+}
+
+int
+tor_upnp_add_tcp_mapping(miniupnpc_state_t *state,
+ uint16_t internal_port, uint16_t external_port)
+{
+ int r;
+ char internal_port_str[6];
+ char external_port_str[6];
+
+ if (!state->init) {
+ r = tor_upnp_init(state);
+ if (r != UPNP_ERR_SUCCESS)
+ return r;
+ }
+
+ snprintf(internal_port_str, sizeof(internal_port_str),
+ "%d", internal_port);
+ snprintf(external_port_str, sizeof(external_port_str),
+ "%d", external_port);
+
+ r = UPNP_AddPortMapping(state->urls.controlURL,
+ state->data.first.servicetype,
+ external_port_str, internal_port_str,
+ state->lanaddr, UPNP_DESC, "TCP", 0);
+ if (r != UPNPCOMMAND_SUCCESS)
+ return UPNP_ERR_ADDPORTMAPPING;
+
+ return UPNP_ERR_SUCCESS;
+}
+
diff --git a/src/tools/tor-fw-helper/tor-fw-helper-upnp.h b/src/tools/tor-fw-helper/tor-fw-helper-upnp.h
new file mode 100644
index 0000000000..aac7452319
--- /dev/null
+++ b/src/tools/tor-fw-helper/tor-fw-helper-upnp.h
@@ -0,0 +1,32 @@
+/* Copyright (c) 2010, Jacob Appelbaum, Steven J. Murdoch.
+ * Copyright (c) 2010, The Tor Project, Inc. */
+/* See LICENSE for licensing information */
+
+#ifndef _TOR_FW_HELPER_UPNP_H
+#define _TOR_FW_HELPER_UPNP_H
+
+#include <miniupnpc/miniwget.h>
+#include <miniupnpc/miniupnpc.h>
+#include <miniupnpc/upnpcommands.h>
+#include <miniupnpc/upnperrors.h>
+
+#define UPNP_LANADDR_SZ 64
+
+typedef struct miniupnpc_state_t {
+ struct UPNPUrls urls;
+ struct IGDdatas data;
+ char lanaddr[UPNP_LANADDR_SZ];
+ int init;
+} miniupnpc_state_t;
+
+int tor_upnp_init(miniupnpc_state_t *state);
+
+int tor_upnp_cleanup(miniupnpc_state_t *state);
+
+int tor_upnp_fetch_public_ip(miniupnpc_state_t *state);
+
+int tor_upnp_add_tcp_mapping(miniupnpc_state_t *state,
+ uint16_t internal_port, uint16_t external_port);
+
+#endif
+
diff --git a/src/tools/tor-fw-helper/tor-fw-helper.c b/src/tools/tor-fw-helper/tor-fw-helper.c
new file mode 100644
index 0000000000..c7cc577e17
--- /dev/null
+++ b/src/tools/tor-fw-helper/tor-fw-helper.c
@@ -0,0 +1,285 @@
+/* Copyright (c) 2010, Jacob Appelbaum, Steven J. Murdoch.
+ * Copyright (c) 2010, The Tor Project, Inc. */
+/* See LICENSE for licensing information */
+
+/*
+ * tor-fw-helper is a tool for opening firewalls with NAT-PMP and UPnP; this
+ * tool is designed to be called by hand or by Tor by way of a exec() at a
+ * later date.
+ */
+
+#include <stdio.h>
+#include <stdint.h>
+#include <stdlib.h>
+#include <getopt.h>
+#include <time.h>
+
+#include "orconfig.h"
+#include "tor-fw-helper.h"
+#include "tor-fw-helper-natpmp.h"
+#include "tor-fw-helper-upnp.h"
+
+static void
+usage(void)
+{
+ fprintf(stderr, "tor-fw-helper usage:\n"
+ " [-h|--help]\n"
+ " [-T|--Test]\n"
+ " [-v|--verbose]\n"
+ " [-g|--fetch-public-ip]\n"
+ " -i|--internal-or-port [TCP port]\n"
+ " [-e|--external-or-port [TCP port]]\n"
+ " [-d|--internal-dir-port [TCP port]\n"
+ " [-p|--external-dir-port [TCP port]]]\n");
+}
+
+/* Log commandline options */
+static int
+test_commandline_options(int argc, char **argv)
+{
+ int i, retval;
+ FILE *logfile;
+ time_t now;
+
+ /* Open the log file */
+ logfile = fopen("tor-fw-helper.log", "a");
+ if (NULL == logfile)
+ return -1;
+
+ /* Send all commandline arguments to the file */
+ now = time(NULL);
+ retval = fprintf(logfile, "START: %s\n", ctime(&now));
+ for (i = 0; i < argc; i++) {
+ retval = fprintf(logfile, "ARG: %d: %s\n", i, argv[i]);
+ if (retval < 0)
+ goto error;
+
+ retval = fprintf(stdout, "ARG: %d: %s\n", i, argv[i]);
+ if (retval < 0)
+ goto error;
+ }
+ now = time(NULL);
+ retval = fprintf(logfile, "END: %s\n", ctime(&now));
+
+ /* Close and clean up */
+ retval = fclose(logfile);
+ return retval;
+
+ /* If there was an error during writing */
+ error:
+ fclose(logfile);
+ return -1;
+}
+
+static void
+tor_fw_fetch_public_ip(tor_fw_options_t *tor_fw_options,
+ miniupnpc_state_t *miniupnpc_state)
+{
+ int r = 0;
+ r = tor_natpmp_fetch_public_ip(tor_fw_options);
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: Attempts to fetch public ip (natpmp) resulted in: "
+ "%d\n", r);
+
+ if (r == 0)
+ tor_fw_options->public_ip_status = 1;
+
+ r = tor_upnp_fetch_public_ip(miniupnpc_state);
+ if (tor_fw_options->verbose)
+ fprintf(stdout, "V: Attempts to fetch public ip (upnp) resulted in: "
+ "%d\n", r);
+
+ if (r == 0)
+ tor_fw_options->public_ip_status = 1;
+}
+
+static void
+tor_fw_add_or_port(tor_fw_options_t *tor_fw_options, miniupnpc_state_t
+ *miniupnpc_state)
+{
+ int r = 0;
+ tor_fw_options->internal_port = tor_fw_options->private_or_port;
+ tor_fw_options->external_port = tor_fw_options->public_or_port;
+
+ r = tor_natpmp_add_tcp_mapping(tor_fw_options);
+ fprintf(stdout, "tor-fw-helper: Attempts to add ORPort mapping (natpmp)"
+ "resulted in: %d\n", r);
+
+ if (r == 0)
+ tor_fw_options->nat_pmp_status = 1;
+
+ r = tor_upnp_add_tcp_mapping(miniupnpc_state,
+ tor_fw_options->private_or_port,
+ tor_fw_options->public_or_port);
+ fprintf(stdout, "tor-fw-helper: Attempts to add ORPort mapping (upnp)"
+ "resulted in: %d\n", r);
+
+ if (r == 0)
+ tor_fw_options->upnp_status = 1;
+}
+
+static void
+tor_fw_add_dir_port(tor_fw_options_t *tor_fw_options, miniupnpc_state_t
+ *miniupnpc_state)
+{
+ int r = 0;
+ tor_fw_options->internal_port = tor_fw_options->private_dir_port;
+ tor_fw_options->external_port = tor_fw_options->public_dir_port;
+
+ r = tor_natpmp_add_tcp_mapping(tor_fw_options);
+ fprintf(stdout, "V: Attempts to add DirPort mapping (natpmp) resulted in: "
+ "%d\n", r);
+
+ r = tor_upnp_add_tcp_mapping(miniupnpc_state,
+ tor_fw_options->private_or_port,
+ tor_fw_options->public_or_port);
+ fprintf(stdout, "V: Attempts to add DirPort mapping (upnp) resulted in: "
+ "%d\n",
+ r);
+}
+
+int
+main(int argc, char **argv)
+{
+ int r = 0;
+ int c = 0;
+
+ tor_fw_options_t tor_fw_options = {0,0,0,0,0,0,0,0,0,0,0,0,0};
+ miniupnpc_state_t miniupnpc_state;
+
+ miniupnpc_state.init = 0;
+
+ while (1)
+ {
+ int option_index = 0;
+ static struct option long_options[] =
+ {
+ {"verbose", 0, 0, 'v'},
+ {"help", 0, 0, 'h'},
+ {"internal-or-port", 1, 0, 'i'},
+ {"external-or-port", 1, 0, 'e'},
+ {"internal-dir-port", 1, 0, 'd'},
+ {"external-dir-port", 1, 0, 'p'},
+ {"fetch-public-ip", 0, 0, 'g'},
+ {"test-commandline", 0, 0, 'T'},
+ {0, 0, 0, 0}
+ };
+
+ c = getopt_long(argc, argv, "vhi:e:d:p:gT",
+ long_options, &option_index);
+ if (c == -1)
+ break;
+
+ switch (c)
+ {
+ case 'v': tor_fw_options.verbose = 1; break;
+ case 'h': tor_fw_options.help = 1; usage(); exit(1); break;
+ case 'i': sscanf(optarg, "%hu", &tor_fw_options.private_or_port);
+ break;
+ case 'e': sscanf(optarg, "%hu", &tor_fw_options.public_or_port);
+ break;
+ case 'd': sscanf(optarg, "%hu", &tor_fw_options.private_dir_port);
+ break;
+ case 'p': sscanf(optarg, "%hu", &tor_fw_options.public_dir_port);
+ break;
+ case 'g': tor_fw_options.fetch_public_ip = 1; break;
+ case 'T': tor_fw_options.test_commandline = 1; break;
+ case '?': break;
+ default : fprintf(stderr, "Unknown option!\n"); usage(); exit(1);
+ }
+ }
+
+ if (tor_fw_options.verbose)
+ {
+ fprintf(stderr, "V: tor-fw-helper version %s\n"
+ "V: We were called with the following arguments:\n"
+ "V: verbose = %d, help = %d, pub or port = %u, "
+ "priv or port = %u\n"
+ "V: pub dir port = %u, priv dir port = %u\n"
+ "V: fetch_public_ip = %u\n",
+ tor_fw_version, tor_fw_options.verbose, tor_fw_options.help,
+ tor_fw_options.private_or_port, tor_fw_options.public_or_port,
+ tor_fw_options.private_dir_port, tor_fw_options.public_dir_port,
+ tor_fw_options.fetch_public_ip);
+ }
+
+ if (tor_fw_options.test_commandline) {
+ return test_commandline_options(argc, argv);
+ }
+
+ /* At the very least, we require an ORPort;
+ Given a private ORPort, we can ask for a mapping that matches the port
+ externally.
+ */
+ if (!tor_fw_options.private_or_port && !tor_fw_options.fetch_public_ip)
+ {
+ fprintf(stderr, "E: We require an ORPort or fetch_public_ip"
+ " request!\n");
+ usage();
+ exit(1);
+ } else {
+ /* When we only have one ORPort, internal/external are
+ set to be the same.*/
+ if (!tor_fw_options.public_or_port && tor_fw_options.private_or_port)
+ {
+ if (tor_fw_options.verbose)
+ fprintf(stdout, "V: We're setting public_or_port = "
+ "private_or_port.\n");
+ tor_fw_options.public_or_port = tor_fw_options.private_or_port;
+ }
+ }
+ if (!tor_fw_options.private_dir_port)
+ {
+ if (tor_fw_options.verbose)
+ fprintf(stdout, "V: We have no DirPort; no hole punching for "
+ "DirPorts\n");
+
+ } else {
+ /* When we only have one DirPort, internal/external are
+ set to be the same.*/
+ if (!tor_fw_options.public_dir_port && tor_fw_options.private_dir_port)
+ {
+ if (tor_fw_options.verbose)
+ fprintf(stdout, "V: We're setting public_or_port = "
+ "private_or_port.\n");
+
+ tor_fw_options.public_dir_port = tor_fw_options.private_dir_port;
+ }
+ }
+
+ if (tor_fw_options.verbose)
+ {
+ fprintf(stdout, "V: pub or port = %u, priv or port = %u\n"
+ "V: pub dir port = %u, priv dir port = %u\n",
+ tor_fw_options.private_or_port, tor_fw_options.public_or_port,
+ tor_fw_options.private_dir_port,
+ tor_fw_options.public_dir_port);
+ }
+
+ if (tor_fw_options.fetch_public_ip)
+ {
+ tor_fw_fetch_public_ip(&tor_fw_options, &miniupnpc_state);
+ }
+
+ if (tor_fw_options.private_or_port)
+ {
+ tor_fw_add_or_port(&tor_fw_options, &miniupnpc_state);
+ }
+
+ if (tor_fw_options.private_dir_port)
+ {
+ tor_fw_add_dir_port(&tor_fw_options, &miniupnpc_state);
+ }
+
+ r = (((tor_fw_options.nat_pmp_status | tor_fw_options.upnp_status)
+ |tor_fw_options.public_ip_status));
+ if (r > 0)
+ {
+ fprintf(stdout, "tor-fw-helper: SUCCESS\n");
+ } else {
+ fprintf(stderr, "tor-fw-helper: FAILURE\n");
+ }
+
+ exit(r);
+}
+
diff --git a/src/tools/tor-fw-helper/tor-fw-helper.h b/src/tools/tor-fw-helper/tor-fw-helper.h
new file mode 100644
index 0000000000..03501459cb
--- /dev/null
+++ b/src/tools/tor-fw-helper/tor-fw-helper.h
@@ -0,0 +1,33 @@
+/* Copyright (c) 2010, Jacob Appelbaum, Steven J. Murdoch.
+ * Copyright (c) 2010, The Tor Project, Inc. */
+/* See LICENSE for licensing information */
+
+#ifndef _TOR_FW_HELPER_H
+#define _TOR_FW_HELPER_H
+
+#include <stdint.h>
+#include <stdio.h>
+#include <stdlib.h>
+#include <getopt.h>
+#include <time.h>
+
+#define tor_fw_version "0.1"
+
+typedef struct {
+ int verbose;
+ int help;
+ int test_commandline;
+ uint16_t private_dir_port;
+ uint16_t private_or_port;
+ uint16_t public_dir_port;
+ uint16_t public_or_port;
+ uint16_t internal_port;
+ uint16_t external_port;
+ int fetch_public_ip;
+ int nat_pmp_status;
+ int upnp_status;
+ int public_ip_status;
+} tor_fw_options_t;
+
+#endif
+