2020-02-05 14:16:58 -08:00
|
|
|
// Copyright (c) 2020 Tailscale Inc & AUTHORS All rights reserved.
|
|
|
|
// Use of this source code is governed by a BSD-style
|
|
|
|
// license that can be found in the LICENSE file.
|
|
|
|
|
2020-11-09 21:22:36 -08:00
|
|
|
// Package filter is a stateful packet filter.
|
2020-02-05 14:16:58 -08:00
|
|
|
package filter
|
|
|
|
|
|
|
|
import (
|
2020-07-30 10:57:30 -07:00
|
|
|
"fmt"
|
2020-02-05 14:16:58 -08:00
|
|
|
"sync"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/golang/groupcache/lru"
|
2020-05-08 12:30:22 -06:00
|
|
|
"golang.org/x/time/rate"
|
2020-11-09 20:12:21 -08:00
|
|
|
"inet.af/netaddr"
|
2020-11-09 16:16:04 -08:00
|
|
|
"tailscale.com/net/packet"
|
Add tstest.PanicOnLog(), and fix various problems detected by this.
If a test calls log.Printf, 'go test' horrifyingly rearranges the
output to no longer be in chronological order, which makes debugging
virtually impossible. Let's stop that from happening by making
log.Printf panic if called from any module, no matter how deep, during
tests.
This required us to change the default error handler in at least one
http.Server, as well as plumbing a bunch of logf functions around,
especially in magicsock and wgengine, but also in logtail and backoff.
To add insult to injury, 'go test' also rearranges the output when a
parent test has multiple sub-tests (all the sub-test's t.Logf is always
printed after all the parent tests t.Logf), so we need to screw around
with a special Logf that can point at the "current" t (current_t.Logf)
in some places. Probably our entire way of using subtests is wrong,
since 'go test' would probably like to run them all in parallel if you
called t.Parallel(), but it definitely can't because the're all
manipulating the shared state created by the parent test. They should
probably all be separate toplevel tests instead, with common
setup/teardown logic. But that's a job for another time.
Signed-off-by: Avery Pennarun <apenwarr@tailscale.com>
2020-05-13 22:59:54 -04:00
|
|
|
"tailscale.com/types/logger"
|
2020-02-05 14:16:58 -08:00
|
|
|
)
|
|
|
|
|
2020-03-25 08:40:36 -07:00
|
|
|
// Filter is a stateful packet filter.
|
2020-02-05 14:16:58 -08:00
|
|
|
type Filter struct {
|
2020-05-22 02:41:18 +00:00
|
|
|
logf logger.Logf
|
2020-11-10 23:23:17 -08:00
|
|
|
// local4 and local6 are the lists of IP prefixes that we know
|
|
|
|
// to be "local" to this node. All packets coming in over
|
|
|
|
// tailscale must have a destination within local4 or local6,
|
|
|
|
// regardless of the policy filter below. Zero values reject
|
|
|
|
// all incoming traffic.
|
2020-11-09 20:12:21 -08:00
|
|
|
local4 []net4
|
2020-11-10 23:23:17 -08:00
|
|
|
local6 []net6
|
|
|
|
// matches4 and matches6 are lists of match->action rules
|
|
|
|
// applied to all packets arriving over tailscale
|
|
|
|
// tunnels. Matches are checked in order, and processing stops
|
|
|
|
// at the first matching rule. The default policy if no rules
|
|
|
|
// match is to drop the packet.
|
2020-11-09 20:12:21 -08:00
|
|
|
matches4 matches4
|
2020-11-10 23:23:17 -08:00
|
|
|
matches6 matches6
|
2020-05-22 02:41:18 +00:00
|
|
|
// state is the connection tracking state attached to this
|
|
|
|
// filter. It is used to allow incoming traffic that is a response
|
|
|
|
// to an outbound connection that this node made, even if those
|
|
|
|
// incoming packets don't get accepted by matches above.
|
2020-11-10 23:23:17 -08:00
|
|
|
state4 *filterState
|
|
|
|
state6 *filterState
|
2020-02-05 14:16:58 -08:00
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
// tuple4 is a 4-tuple of source and destination IPv4 and port. It's
|
2020-11-09 21:22:36 -08:00
|
|
|
// used as a lookup key in filterState.
|
2020-11-10 23:23:17 -08:00
|
|
|
type tuple4 struct {
|
2020-11-09 21:22:36 -08:00
|
|
|
SrcIP packet.IP4
|
|
|
|
DstIP packet.IP4
|
|
|
|
SrcPort uint16
|
|
|
|
DstPort uint16
|
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
// tuple6 is a 4-tuple of source and destination IPv6 and port. It's
|
|
|
|
// used as a lookup key in filterState.
|
|
|
|
type tuple6 struct {
|
|
|
|
SrcIP packet.IP6
|
|
|
|
DstIP packet.IP6
|
|
|
|
SrcPort uint16
|
|
|
|
DstPort uint16
|
|
|
|
}
|
|
|
|
|
2020-11-09 21:22:36 -08:00
|
|
|
// filterState is a state cache of past seen packets.
|
|
|
|
type filterState struct {
|
|
|
|
mu sync.Mutex
|
2020-11-10 23:23:17 -08:00
|
|
|
lru *lru.Cache // of tuple4 or tuple6
|
2020-11-09 21:22:36 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
// lruMax is the size of the LRU cache in filterState.
|
|
|
|
const lruMax = 512
|
|
|
|
|
|
|
|
// Response is a verdict from the packet filter.
|
2020-02-05 14:16:58 -08:00
|
|
|
type Response int
|
|
|
|
|
|
|
|
const (
|
2020-11-09 21:22:36 -08:00
|
|
|
Drop Response = iota // do not continue processing packet.
|
|
|
|
Accept // continue processing packet.
|
|
|
|
noVerdict // no verdict yet, continue running filter
|
2020-02-05 14:16:58 -08:00
|
|
|
)
|
|
|
|
|
|
|
|
func (r Response) String() string {
|
|
|
|
switch r {
|
|
|
|
case Drop:
|
|
|
|
return "Drop"
|
|
|
|
case Accept:
|
|
|
|
return "Accept"
|
|
|
|
case noVerdict:
|
|
|
|
return "noVerdict"
|
|
|
|
default:
|
|
|
|
return "???"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-03-25 08:40:36 -07:00
|
|
|
// RunFlags controls the filter's debug log verbosity at runtime.
|
2020-02-05 14:16:58 -08:00
|
|
|
type RunFlags int
|
|
|
|
|
|
|
|
const (
|
2020-11-09 21:22:36 -08:00
|
|
|
LogDrops RunFlags = 1 << iota // write dropped packet info to logf
|
|
|
|
LogAccepts // write accepted packet info to logf
|
|
|
|
HexdumpDrops // print packet hexdump when logging drops
|
|
|
|
HexdumpAccepts // print packet hexdump when logging accepts
|
2020-02-05 14:16:58 -08:00
|
|
|
)
|
|
|
|
|
2020-11-09 22:02:03 -08:00
|
|
|
// NewAllowAllForTest returns a packet filter that accepts
|
|
|
|
// everything. Use in tests only, as it permits some kinds of spoofing
|
|
|
|
// attacks to reach the OS network stack.
|
|
|
|
func NewAllowAllForTest(logf logger.Logf) *Filter {
|
2020-11-10 23:23:17 -08:00
|
|
|
any4 := netaddr.IPPrefix{IP: netaddr.IPv4(0, 0, 0, 0), Bits: 0}
|
|
|
|
any6 := netaddr.IPPrefix{IP: netaddr.IPFrom16([16]byte{}), Bits: 0}
|
|
|
|
ms := []Match{
|
|
|
|
{
|
|
|
|
Srcs: []netaddr.IPPrefix{any4},
|
|
|
|
Dsts: []NetPortRange{
|
|
|
|
{
|
|
|
|
Net: any4,
|
|
|
|
Ports: PortRange{
|
|
|
|
First: 0,
|
|
|
|
Last: 65535,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Srcs: []netaddr.IPPrefix{any6},
|
|
|
|
Dsts: []NetPortRange{
|
|
|
|
{
|
|
|
|
Net: any6,
|
|
|
|
Ports: PortRange{
|
|
|
|
First: 0,
|
|
|
|
Last: 65535,
|
|
|
|
},
|
2020-11-09 22:02:03 -08:00
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
return New(ms, []netaddr.IPPrefix{any4, any6}, nil, logf)
|
2020-02-05 14:16:58 -08:00
|
|
|
}
|
|
|
|
|
2020-03-25 08:40:36 -07:00
|
|
|
// NewAllowNone returns a packet filter that rejects everything.
|
Add tstest.PanicOnLog(), and fix various problems detected by this.
If a test calls log.Printf, 'go test' horrifyingly rearranges the
output to no longer be in chronological order, which makes debugging
virtually impossible. Let's stop that from happening by making
log.Printf panic if called from any module, no matter how deep, during
tests.
This required us to change the default error handler in at least one
http.Server, as well as plumbing a bunch of logf functions around,
especially in magicsock and wgengine, but also in logtail and backoff.
To add insult to injury, 'go test' also rearranges the output when a
parent test has multiple sub-tests (all the sub-test's t.Logf is always
printed after all the parent tests t.Logf), so we need to screw around
with a special Logf that can point at the "current" t (current_t.Logf)
in some places. Probably our entire way of using subtests is wrong,
since 'go test' would probably like to run them all in parallel if you
called t.Parallel(), but it definitely can't because the're all
manipulating the shared state created by the parent test. They should
probably all be separate toplevel tests instead, with common
setup/teardown logic. But that's a job for another time.
Signed-off-by: Avery Pennarun <apenwarr@tailscale.com>
2020-05-13 22:59:54 -04:00
|
|
|
func NewAllowNone(logf logger.Logf) *Filter {
|
2020-05-22 02:41:18 +00:00
|
|
|
return New(nil, nil, nil, logf)
|
2020-02-05 14:16:58 -08:00
|
|
|
}
|
|
|
|
|
2020-05-22 02:41:18 +00:00
|
|
|
// New creates a new packet filter. The filter enforces that incoming
|
|
|
|
// packets must be destined to an IP in localNets, and must be allowed
|
|
|
|
// by matches. If shareStateWith is non-nil, the returned filter
|
2020-11-09 21:22:36 -08:00
|
|
|
// shares state with the previous one, to enable changing rules at
|
|
|
|
// runtime without breaking existing stateful flows.
|
2020-11-09 21:33:41 -08:00
|
|
|
func New(matches []Match, localNets []netaddr.IPPrefix, shareStateWith *Filter, logf logger.Logf) *Filter {
|
2020-11-10 23:23:17 -08:00
|
|
|
var state4, state6 *filterState
|
2020-03-25 03:47:55 -04:00
|
|
|
if shareStateWith != nil {
|
2020-11-10 23:23:17 -08:00
|
|
|
state4 = shareStateWith.state4
|
|
|
|
state6 = shareStateWith.state6
|
2020-03-25 03:47:55 -04:00
|
|
|
} else {
|
2020-11-10 23:23:17 -08:00
|
|
|
state4 = &filterState{
|
|
|
|
lru: lru.New(lruMax),
|
|
|
|
}
|
|
|
|
state6 = &filterState{
|
2020-03-25 08:40:36 -07:00
|
|
|
lru: lru.New(lruMax),
|
2020-03-25 03:47:55 -04:00
|
|
|
}
|
|
|
|
}
|
2020-02-05 14:16:58 -08:00
|
|
|
f := &Filter{
|
2020-11-09 20:12:21 -08:00
|
|
|
logf: logf,
|
|
|
|
matches4: newMatches4(matches),
|
2020-11-10 23:23:17 -08:00
|
|
|
matches6: newMatches6(matches),
|
2020-11-09 20:12:21 -08:00
|
|
|
local4: nets4FromIPPrefixes(localNets),
|
2020-11-10 23:23:17 -08:00
|
|
|
local6: nets6FromIPPrefixes(localNets),
|
|
|
|
state4: state4,
|
|
|
|
state6: state6,
|
2020-02-05 14:16:58 -08:00
|
|
|
}
|
|
|
|
return f
|
|
|
|
}
|
|
|
|
|
|
|
|
func maybeHexdump(flag RunFlags, b []byte) string {
|
2020-05-08 12:30:22 -06:00
|
|
|
if flag == 0 {
|
2020-02-05 14:16:58 -08:00
|
|
|
return ""
|
|
|
|
}
|
2020-05-08 12:30:22 -06:00
|
|
|
return packet.Hexdump(b) + "\n"
|
2020-02-05 14:16:58 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
// TODO(apenwarr): use a bigger bucket for specifically TCP SYN accept logging?
|
|
|
|
// Logging is a quick way to record every newly opened TCP connection, but
|
|
|
|
// we have to be cautious about flooding the logs vs letting people use
|
|
|
|
// flood protection to hide their traffic. We could use a rate limiter in
|
|
|
|
// the actual *filter* for SYN accepts, perhaps.
|
2020-05-08 12:30:22 -06:00
|
|
|
var acceptBucket = rate.NewLimiter(rate.Every(10*time.Second), 3)
|
|
|
|
var dropBucket = rate.NewLimiter(rate.Every(5*time.Second), 10)
|
2020-02-05 14:16:58 -08:00
|
|
|
|
2020-11-09 23:49:09 -08:00
|
|
|
func (f *Filter) logRateLimit(runflags RunFlags, q *packet.Parsed, dir direction, r Response, why string) {
|
2020-06-02 08:09:20 -04:00
|
|
|
var verdict string
|
|
|
|
|
2020-07-30 10:57:30 -07:00
|
|
|
if r == Drop && omitDropLogging(q, dir) {
|
2020-07-28 22:10:58 -07:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2020-05-08 12:30:22 -06:00
|
|
|
if r == Drop && (runflags&LogDrops) != 0 && dropBucket.Allow() {
|
2020-06-02 08:09:20 -04:00
|
|
|
verdict = "Drop"
|
|
|
|
runflags &= HexdumpDrops
|
|
|
|
} else if r == Accept && (runflags&LogAccepts) != 0 && acceptBucket.Allow() {
|
|
|
|
verdict = "Accept"
|
|
|
|
runflags &= HexdumpAccepts
|
|
|
|
}
|
|
|
|
|
|
|
|
// Note: it is crucial that q.String() be called only if {accept,drop}Bucket.Allow() passes,
|
|
|
|
// since it causes an allocation.
|
|
|
|
if verdict != "" {
|
2020-06-08 18:19:26 -04:00
|
|
|
b := q.Buffer()
|
|
|
|
f.logf("%s: %s %d %s\n%s", verdict, q.String(), len(b), why, maybeHexdump(runflags, b))
|
2020-02-05 14:16:58 -08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-11-09 23:22:23 -08:00
|
|
|
// dummyPacket is a 20-byte slice of garbage, to pass the filter
|
|
|
|
// pre-check when evaluating synthesized packets.
|
|
|
|
var dummyPacket = []byte{
|
|
|
|
0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
|
|
|
|
0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
|
|
|
|
}
|
|
|
|
|
|
|
|
// CheckTCP determines whether TCP traffic from srcIP to dstIP:dstPort
|
|
|
|
// is allowed.
|
|
|
|
func (f *Filter) CheckTCP(srcIP, dstIP netaddr.IP, dstPort uint16) Response {
|
2020-11-09 23:49:09 -08:00
|
|
|
pkt := &packet.Parsed{}
|
2020-11-09 23:22:23 -08:00
|
|
|
pkt.Decode(dummyPacket) // initialize private fields
|
2020-11-10 23:23:17 -08:00
|
|
|
switch {
|
|
|
|
case (srcIP.Is4() && dstIP.Is6()) || (srcIP.Is6() && srcIP.Is4()):
|
|
|
|
// Mistmatched address families, no filters will
|
|
|
|
// match.
|
|
|
|
return Drop
|
|
|
|
case srcIP.Is4():
|
|
|
|
pkt.IPVersion = 4
|
|
|
|
pkt.SrcIP4 = packet.IP4FromNetaddr(srcIP)
|
|
|
|
pkt.DstIP4 = packet.IP4FromNetaddr(dstIP)
|
|
|
|
case srcIP.Is6():
|
|
|
|
pkt.IPVersion = 6
|
|
|
|
pkt.SrcIP6 = packet.IP6FromNetaddr(srcIP)
|
|
|
|
pkt.DstIP6 = packet.IP6FromNetaddr(dstIP)
|
|
|
|
default:
|
|
|
|
panic("unreachable")
|
|
|
|
}
|
2020-11-09 23:22:23 -08:00
|
|
|
pkt.IPProto = packet.TCP
|
|
|
|
pkt.TCPFlags = packet.TCPSyn
|
|
|
|
pkt.SrcPort = 0
|
|
|
|
pkt.DstPort = dstPort
|
|
|
|
|
|
|
|
return f.RunIn(pkt, 0)
|
|
|
|
}
|
|
|
|
|
2020-11-09 21:22:36 -08:00
|
|
|
// RunIn determines whether this node is allowed to receive q from a
|
|
|
|
// Tailscale peer.
|
2020-11-09 23:49:09 -08:00
|
|
|
func (f *Filter) RunIn(q *packet.Parsed, rf RunFlags) Response {
|
2020-07-28 22:10:58 -07:00
|
|
|
dir := in
|
|
|
|
r := f.pre(q, rf, dir)
|
2020-02-05 14:16:58 -08:00
|
|
|
if r == Accept || r == Drop {
|
|
|
|
// already logged
|
|
|
|
return r
|
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
var why string
|
|
|
|
switch q.IPVersion {
|
|
|
|
case 4:
|
|
|
|
r, why = f.runIn4(q)
|
|
|
|
case 6:
|
|
|
|
r, why = f.runIn6(q)
|
|
|
|
default:
|
|
|
|
r, why = Drop, "not-ip"
|
|
|
|
}
|
2020-07-28 22:10:58 -07:00
|
|
|
f.logRateLimit(rf, q, dir, r, why)
|
2020-02-05 14:16:58 -08:00
|
|
|
return r
|
|
|
|
}
|
|
|
|
|
2020-11-09 21:22:36 -08:00
|
|
|
// RunOut determines whether this node is allowed to send q to a
|
|
|
|
// Tailscale peer.
|
2020-11-09 23:49:09 -08:00
|
|
|
func (f *Filter) RunOut(q *packet.Parsed, rf RunFlags) Response {
|
2020-07-28 22:10:58 -07:00
|
|
|
dir := out
|
|
|
|
r := f.pre(q, rf, dir)
|
2020-02-05 14:16:58 -08:00
|
|
|
if r == Drop || r == Accept {
|
|
|
|
// already logged
|
|
|
|
return r
|
|
|
|
}
|
|
|
|
r, why := f.runOut(q)
|
2020-07-28 22:10:58 -07:00
|
|
|
f.logRateLimit(rf, q, dir, r, why)
|
2020-02-05 14:16:58 -08:00
|
|
|
return r
|
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
func (f *Filter) runIn4(q *packet.Parsed) (r Response, why string) {
|
2020-05-22 02:41:18 +00:00
|
|
|
// A compromised peer could try to send us packets for
|
|
|
|
// destinations we didn't explicitly advertise. This check is to
|
|
|
|
// prevent that.
|
2020-11-10 00:04:27 -08:00
|
|
|
if !ip4InList(q.DstIP4, f.local4) {
|
2020-05-22 02:41:18 +00:00
|
|
|
return Drop, "destination not allowed"
|
|
|
|
}
|
|
|
|
|
2020-02-05 14:16:58 -08:00
|
|
|
switch q.IPProto {
|
2020-11-10 01:00:35 -08:00
|
|
|
case packet.ICMPv4:
|
2020-04-29 03:53:32 -04:00
|
|
|
if q.IsEchoResponse() || q.IsError() {
|
|
|
|
// ICMP responses are allowed.
|
|
|
|
// TODO(apenwarr): consider using conntrack state.
|
|
|
|
// We could choose to reject all packets that aren't
|
|
|
|
// related to an existing ICMP-Echo, TCP, or UDP
|
|
|
|
// session.
|
|
|
|
return Accept, "icmp response ok"
|
2020-11-09 20:12:21 -08:00
|
|
|
} else if f.matches4.matchIPsOnly(q) {
|
2020-04-29 03:53:32 -04:00
|
|
|
// If any port is open to an IP, allow ICMP to it.
|
2020-02-05 14:16:58 -08:00
|
|
|
return Accept, "icmp ok"
|
|
|
|
}
|
|
|
|
case packet.TCP:
|
|
|
|
// For TCP, we want to allow *outgoing* connections,
|
|
|
|
// which means we want to allow return packets on those
|
|
|
|
// connections. To make this restriction work, we need to
|
|
|
|
// allow non-SYN packets (continuation of an existing session)
|
|
|
|
// to arrive. This should be okay since a new incoming session
|
|
|
|
// can't be initiated without first sending a SYN.
|
|
|
|
// It happens to also be much faster.
|
|
|
|
// TODO(apenwarr): Skip the rest of decoding in this path?
|
|
|
|
if q.IPProto == packet.TCP && !q.IsTCPSyn() {
|
|
|
|
return Accept, "tcp non-syn"
|
|
|
|
}
|
2020-11-09 20:12:21 -08:00
|
|
|
if f.matches4.match(q) {
|
2020-02-05 14:16:58 -08:00
|
|
|
return Accept, "tcp ok"
|
|
|
|
}
|
|
|
|
case packet.UDP:
|
2020-11-10 23:23:17 -08:00
|
|
|
t := tuple4{q.SrcIP4, q.DstIP4, q.SrcPort, q.DstPort}
|
2020-02-05 14:16:58 -08:00
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
f.state4.mu.Lock()
|
|
|
|
_, ok := f.state4.lru.Get(t)
|
|
|
|
f.state4.mu.Unlock()
|
2020-02-05 14:16:58 -08:00
|
|
|
|
|
|
|
if ok {
|
|
|
|
return Accept, "udp cached"
|
|
|
|
}
|
2020-11-09 20:12:21 -08:00
|
|
|
if f.matches4.match(q) {
|
2020-02-05 14:16:58 -08:00
|
|
|
return Accept, "udp ok"
|
|
|
|
}
|
|
|
|
default:
|
|
|
|
return Drop, "Unknown proto"
|
|
|
|
}
|
|
|
|
return Drop, "no rules matched"
|
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
func (f *Filter) runIn6(q *packet.Parsed) (r Response, why string) {
|
|
|
|
// A compromised peer could try to send us packets for
|
|
|
|
// destinations we didn't explicitly advertise. This check is to
|
|
|
|
// prevent that.
|
|
|
|
if !ip6InList(q.DstIP6, f.local6) {
|
|
|
|
return Drop, "destination not allowed"
|
|
|
|
}
|
|
|
|
|
|
|
|
switch q.IPProto {
|
|
|
|
case packet.ICMPv6:
|
|
|
|
if q.IsEchoResponse() || q.IsError() {
|
|
|
|
// ICMP responses are allowed.
|
|
|
|
// TODO(apenwarr): consider using conntrack state.
|
|
|
|
// We could choose to reject all packets that aren't
|
|
|
|
// related to an existing ICMP-Echo, TCP, or UDP
|
|
|
|
// session.
|
|
|
|
return Accept, "icmp response ok"
|
|
|
|
} else if f.matches6.matchIPsOnly(q) {
|
|
|
|
// If any port is open to an IP, allow ICMP to it.
|
|
|
|
return Accept, "icmp ok"
|
|
|
|
}
|
|
|
|
case packet.TCP:
|
|
|
|
// For TCP, we want to allow *outgoing* connections,
|
|
|
|
// which means we want to allow return packets on those
|
|
|
|
// connections. To make this restriction work, we need to
|
|
|
|
// allow non-SYN packets (continuation of an existing session)
|
|
|
|
// to arrive. This should be okay since a new incoming session
|
|
|
|
// can't be initiated without first sending a SYN.
|
|
|
|
// It happens to also be much faster.
|
|
|
|
// TODO(apenwarr): Skip the rest of decoding in this path?
|
|
|
|
if q.IPProto == packet.TCP && !q.IsTCPSyn() {
|
|
|
|
return Accept, "tcp non-syn"
|
|
|
|
}
|
|
|
|
if f.matches6.match(q) {
|
|
|
|
return Accept, "tcp ok"
|
|
|
|
}
|
|
|
|
case packet.UDP:
|
|
|
|
t := tuple6{q.SrcIP6, q.DstIP6, q.SrcPort, q.DstPort}
|
|
|
|
|
|
|
|
f.state6.mu.Lock()
|
|
|
|
_, ok := f.state6.lru.Get(t)
|
|
|
|
f.state6.mu.Unlock()
|
|
|
|
|
|
|
|
if ok {
|
|
|
|
return Accept, "udp cached"
|
|
|
|
}
|
|
|
|
if f.matches6.match(q) {
|
|
|
|
return Accept, "udp ok"
|
|
|
|
}
|
|
|
|
default:
|
|
|
|
return Drop, "Unknown proto"
|
|
|
|
}
|
|
|
|
return Drop, "no rules matched"
|
|
|
|
}
|
|
|
|
|
2020-11-09 21:22:36 -08:00
|
|
|
// runIn runs the output-specific part of the filter logic.
|
2020-11-09 23:49:09 -08:00
|
|
|
func (f *Filter) runOut(q *packet.Parsed) (r Response, why string) {
|
2020-11-10 23:23:17 -08:00
|
|
|
if q.IPProto != packet.UDP {
|
|
|
|
return Accept, "ok out"
|
|
|
|
}
|
2020-02-05 14:16:58 -08:00
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
switch q.IPVersion {
|
|
|
|
case 4:
|
|
|
|
t := tuple4{q.DstIP4, q.SrcIP4, q.DstPort, q.SrcPort}
|
|
|
|
var ti interface{} = t // allocate once, rather than twice inside mutex
|
|
|
|
f.state4.mu.Lock()
|
|
|
|
f.state4.lru.Add(ti, ti)
|
|
|
|
f.state4.mu.Unlock()
|
|
|
|
case 6:
|
|
|
|
t := tuple6{q.DstIP6, q.SrcIP6, q.DstPort, q.SrcPort}
|
|
|
|
var ti interface{} = t // allocate once, rather than twice inside mutex
|
|
|
|
f.state6.mu.Lock()
|
|
|
|
f.state6.lru.Add(ti, ti)
|
|
|
|
f.state6.mu.Unlock()
|
2020-02-05 14:16:58 -08:00
|
|
|
}
|
|
|
|
return Accept, "ok out"
|
|
|
|
}
|
|
|
|
|
2020-11-09 21:22:36 -08:00
|
|
|
// direction is whether a packet was flowing in to this machine, or
|
|
|
|
// flowing out.
|
2020-07-28 22:10:58 -07:00
|
|
|
type direction int
|
|
|
|
|
|
|
|
const (
|
2020-11-09 21:22:36 -08:00
|
|
|
in direction = iota // from Tailscale peer to local machine
|
|
|
|
out // from local machine to Tailscale peer
|
2020-07-28 22:10:58 -07:00
|
|
|
)
|
|
|
|
|
2020-07-30 10:57:30 -07:00
|
|
|
func (d direction) String() string {
|
|
|
|
switch d {
|
|
|
|
case in:
|
|
|
|
return "in"
|
|
|
|
case out:
|
|
|
|
return "out"
|
|
|
|
default:
|
|
|
|
return fmt.Sprintf("[??dir=%d]", int(d))
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-11-09 21:22:36 -08:00
|
|
|
// pre runs the direction-agnostic filter logic. dir is only used for
|
|
|
|
// logging.
|
2020-11-09 23:49:09 -08:00
|
|
|
func (f *Filter) pre(q *packet.Parsed, rf RunFlags, dir direction) Response {
|
2020-06-08 18:19:26 -04:00
|
|
|
if len(q.Buffer()) == 0 {
|
2020-02-05 14:16:58 -08:00
|
|
|
// wireguard keepalive packet, always permit.
|
|
|
|
return Accept
|
|
|
|
}
|
2020-06-08 18:19:26 -04:00
|
|
|
if len(q.Buffer()) < 20 {
|
2020-07-28 22:10:58 -07:00
|
|
|
f.logRateLimit(rf, q, dir, Drop, "too short")
|
2020-02-05 14:16:58 -08:00
|
|
|
return Drop
|
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
switch q.IPVersion {
|
|
|
|
case 4:
|
|
|
|
if q.DstIP4.IsMulticast() {
|
|
|
|
f.logRateLimit(rf, q, dir, Drop, "multicast")
|
|
|
|
return Drop
|
|
|
|
}
|
|
|
|
if q.DstIP4.IsLinkLocalUnicast() {
|
|
|
|
f.logRateLimit(rf, q, dir, Drop, "link-local-unicast")
|
|
|
|
return Drop
|
|
|
|
}
|
|
|
|
case 6:
|
|
|
|
if q.DstIP6.IsMulticast() {
|
|
|
|
f.logRateLimit(rf, q, dir, Drop, "multicast")
|
|
|
|
return Drop
|
|
|
|
}
|
|
|
|
if q.DstIP6.IsLinkLocalUnicast() {
|
|
|
|
f.logRateLimit(rf, q, dir, Drop, "link-local-unicast")
|
|
|
|
return Drop
|
|
|
|
}
|
2020-09-25 11:47:38 -07:00
|
|
|
}
|
2020-09-25 11:06:48 -07:00
|
|
|
|
2020-06-04 18:42:44 -04:00
|
|
|
switch q.IPProto {
|
|
|
|
case packet.Unknown:
|
|
|
|
// Unknown packets are dangerous; always drop them.
|
2020-07-28 22:10:58 -07:00
|
|
|
f.logRateLimit(rf, q, dir, Drop, "unknown")
|
2020-06-04 18:42:44 -04:00
|
|
|
return Drop
|
|
|
|
case packet.Fragment:
|
2020-02-05 14:16:58 -08:00
|
|
|
// Fragments after the first always need to be passed through.
|
2020-11-09 23:49:09 -08:00
|
|
|
// Very small fragments are considered Junk by Parsed.
|
2020-07-28 22:10:58 -07:00
|
|
|
f.logRateLimit(rf, q, dir, Accept, "fragment")
|
2020-02-05 14:16:58 -08:00
|
|
|
return Accept
|
|
|
|
}
|
|
|
|
|
|
|
|
return noVerdict
|
|
|
|
}
|
2020-07-28 22:10:58 -07:00
|
|
|
|
|
|
|
// omitDropLogging reports whether packet p, which has already been
|
2020-11-09 20:12:21 -08:00
|
|
|
// deemed a packet to Drop, should bypass the [rate-limited] logging.
|
|
|
|
// We don't want to log scary & spammy reject warnings for packets
|
|
|
|
// that are totally normal, like IPv6 route announcements.
|
2020-11-09 23:49:09 -08:00
|
|
|
func omitDropLogging(p *packet.Parsed, dir direction) bool {
|
2020-11-10 23:23:17 -08:00
|
|
|
if dir != out {
|
|
|
|
return false
|
2020-07-28 22:10:58 -07:00
|
|
|
}
|
|
|
|
|
2020-11-10 23:23:17 -08:00
|
|
|
switch p.IPVersion {
|
|
|
|
case 4:
|
|
|
|
return p.DstIP4.IsMulticast() || p.DstIP4.IsLinkLocalUnicast() || p.IPProto == packet.IGMP
|
|
|
|
case 6:
|
|
|
|
return p.DstIP6.IsMulticast() || p.DstIP6.IsLinkLocalUnicast()
|
|
|
|
default:
|
|
|
|
return false
|
|
|
|
}
|
2020-07-28 22:10:58 -07:00
|
|
|
}
|