2021-07-05 13:14:12 -05:00
|
|
|
package ipv6rwc
|
2021-06-13 04:22:21 -05:00
|
|
|
|
|
|
|
import (
|
|
|
|
"crypto/ed25519"
|
|
|
|
"errors"
|
|
|
|
"fmt"
|
2021-06-25 21:15:40 -05:00
|
|
|
"net"
|
2021-06-13 04:22:21 -05:00
|
|
|
"sync"
|
|
|
|
"time"
|
|
|
|
|
2021-06-13 05:25:13 -05:00
|
|
|
"golang.org/x/net/icmp"
|
|
|
|
"golang.org/x/net/ipv6"
|
|
|
|
|
2021-06-13 04:22:21 -05:00
|
|
|
iwt "github.com/Arceliar/ironwood/types"
|
|
|
|
|
|
|
|
"github.com/yggdrasil-network/yggdrasil-go/src/address"
|
2021-07-05 13:14:12 -05:00
|
|
|
"github.com/yggdrasil-network/yggdrasil-go/src/core"
|
2021-06-13 04:22:21 -05:00
|
|
|
)
|
|
|
|
|
|
|
|
const keyStoreTimeout = 2 * time.Minute
|
|
|
|
|
2021-07-05 13:14:12 -05:00
|
|
|
// Out-of-band packet types
|
|
|
|
const (
|
|
|
|
typeKeyDummy = iota // nolint:deadcode,varcheck
|
|
|
|
typeKeyLookup
|
|
|
|
typeKeyResponse
|
|
|
|
)
|
|
|
|
|
2021-06-13 04:22:21 -05:00
|
|
|
type keyArray [ed25519.PublicKeySize]byte
|
|
|
|
|
|
|
|
type keyStore struct {
|
2021-07-05 13:14:12 -05:00
|
|
|
core *core.Core
|
2021-06-13 04:22:21 -05:00
|
|
|
address address.Address
|
|
|
|
subnet address.Subnet
|
|
|
|
mutex sync.Mutex
|
|
|
|
keyToInfo map[keyArray]*keyInfo
|
|
|
|
addrToInfo map[address.Address]*keyInfo
|
2023-03-26 16:12:45 -05:00
|
|
|
//addrBuffer map[address.Address]*buffer
|
2021-06-13 04:22:21 -05:00
|
|
|
subnetToInfo map[address.Subnet]*keyInfo
|
2023-03-26 16:12:45 -05:00
|
|
|
//subnetBuffer map[address.Subnet]*buffer
|
2021-06-13 05:25:13 -05:00
|
|
|
mtu uint64
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
type keyInfo struct {
|
|
|
|
key keyArray
|
|
|
|
address address.Address
|
|
|
|
subnet address.Subnet
|
|
|
|
timeout *time.Timer // From calling a time.AfterFunc to do cleanup
|
|
|
|
}
|
|
|
|
|
|
|
|
type buffer struct {
|
2021-06-19 07:44:37 -05:00
|
|
|
packet []byte
|
2021-06-13 04:22:21 -05:00
|
|
|
timeout *time.Timer
|
|
|
|
}
|
|
|
|
|
2021-07-05 13:14:12 -05:00
|
|
|
func (k *keyStore) init(c *core.Core) {
|
|
|
|
k.core = c
|
|
|
|
k.address = *address.AddrForKey(k.core.PublicKey())
|
|
|
|
k.subnet = *address.SubnetForKey(k.core.PublicKey())
|
2023-03-19 10:33:07 +00:00
|
|
|
/*if err := k.core.SetOutOfBandHandler(k.oobHandler); err != nil {
|
2021-06-13 04:54:06 -05:00
|
|
|
err = fmt.Errorf("tun.core.SetOutOfBandHander: %w", err)
|
|
|
|
panic(err)
|
2023-03-19 10:33:07 +00:00
|
|
|
}*/
|
2021-06-13 04:22:21 -05:00
|
|
|
k.keyToInfo = make(map[keyArray]*keyInfo)
|
|
|
|
k.addrToInfo = make(map[address.Address]*keyInfo)
|
2023-03-26 16:12:45 -05:00
|
|
|
//k.addrBuffer = make(map[address.Address]*buffer)
|
2021-06-13 04:22:21 -05:00
|
|
|
k.subnetToInfo = make(map[address.Subnet]*keyInfo)
|
2023-03-26 16:12:45 -05:00
|
|
|
//k.subnetBuffer = make(map[address.Subnet]*buffer)
|
2021-06-13 05:25:13 -05:00
|
|
|
k.mtu = 1280 // Default to something safe, expect user to set this
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) sendToAddress(addr address.Address, bs []byte) {
|
|
|
|
k.mutex.Lock()
|
|
|
|
if info := k.addrToInfo[addr]; info != nil {
|
|
|
|
k.resetTimeout(info)
|
|
|
|
k.mutex.Unlock()
|
2021-07-05 13:14:12 -05:00
|
|
|
_, _ = k.core.WriteTo(bs, iwt.Addr(info.key[:]))
|
2021-06-13 04:22:21 -05:00
|
|
|
} else {
|
2023-03-26 16:12:45 -05:00
|
|
|
/*
|
|
|
|
var buf *buffer
|
|
|
|
if buf = k.addrBuffer[addr]; buf == nil {
|
|
|
|
buf = new(buffer)
|
|
|
|
k.addrBuffer[addr] = buf
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
2023-03-26 16:12:45 -05:00
|
|
|
msg := append([]byte(nil), bs...)
|
|
|
|
buf.packet = msg
|
|
|
|
if buf.timeout != nil {
|
|
|
|
buf.timeout.Stop()
|
|
|
|
}
|
|
|
|
buf.timeout = time.AfterFunc(keyStoreTimeout, func() {
|
|
|
|
k.mutex.Lock()
|
|
|
|
defer k.mutex.Unlock()
|
|
|
|
if nbuf := k.addrBuffer[addr]; nbuf == buf {
|
|
|
|
delete(k.addrBuffer, addr)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
k.mutex.Unlock()
|
|
|
|
k.sendKeyLookup(addr.GetKey())
|
|
|
|
*/
|
2021-06-13 04:22:21 -05:00
|
|
|
k.mutex.Unlock()
|
2023-03-26 16:12:45 -05:00
|
|
|
key := k.core.GetKeyFor(addr.GetKey())
|
|
|
|
info := k.update(key)
|
|
|
|
if info.address == addr {
|
|
|
|
_, _ = k.core.WriteTo(bs, iwt.Addr(info.key[:]))
|
|
|
|
}
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) sendToSubnet(subnet address.Subnet, bs []byte) {
|
|
|
|
k.mutex.Lock()
|
|
|
|
if info := k.subnetToInfo[subnet]; info != nil {
|
|
|
|
k.resetTimeout(info)
|
|
|
|
k.mutex.Unlock()
|
2021-07-05 13:14:12 -05:00
|
|
|
_, _ = k.core.WriteTo(bs, iwt.Addr(info.key[:]))
|
2021-06-13 04:22:21 -05:00
|
|
|
} else {
|
2023-03-26 16:12:45 -05:00
|
|
|
/*
|
|
|
|
var buf *buffer
|
|
|
|
if buf = k.subnetBuffer[subnet]; buf == nil {
|
|
|
|
buf = new(buffer)
|
|
|
|
k.subnetBuffer[subnet] = buf
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
2023-03-26 16:12:45 -05:00
|
|
|
msg := append([]byte(nil), bs...)
|
|
|
|
buf.packet = msg
|
|
|
|
if buf.timeout != nil {
|
|
|
|
buf.timeout.Stop()
|
|
|
|
}
|
|
|
|
buf.timeout = time.AfterFunc(keyStoreTimeout, func() {
|
|
|
|
k.mutex.Lock()
|
|
|
|
defer k.mutex.Unlock()
|
|
|
|
if nbuf := k.subnetBuffer[subnet]; nbuf == buf {
|
|
|
|
delete(k.subnetBuffer, subnet)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
k.mutex.Unlock()
|
|
|
|
k.sendKeyLookup(subnet.GetKey())
|
|
|
|
*/
|
2021-06-13 04:22:21 -05:00
|
|
|
k.mutex.Unlock()
|
2023-03-26 16:12:45 -05:00
|
|
|
key := k.core.GetKeyFor(subnet.GetKey())
|
|
|
|
info := k.update(key)
|
|
|
|
if info.subnet == subnet {
|
|
|
|
_, _ = k.core.WriteTo(bs, iwt.Addr(info.key[:]))
|
|
|
|
}
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) update(key ed25519.PublicKey) *keyInfo {
|
|
|
|
k.mutex.Lock()
|
|
|
|
var kArray keyArray
|
|
|
|
copy(kArray[:], key)
|
|
|
|
var info *keyInfo
|
2021-09-23 04:39:12 -05:00
|
|
|
var packets [][]byte
|
2021-06-13 04:22:21 -05:00
|
|
|
if info = k.keyToInfo[kArray]; info == nil {
|
|
|
|
info = new(keyInfo)
|
|
|
|
info.key = kArray
|
|
|
|
info.address = *address.AddrForKey(ed25519.PublicKey(info.key[:]))
|
|
|
|
info.subnet = *address.SubnetForKey(ed25519.PublicKey(info.key[:]))
|
|
|
|
k.keyToInfo[info.key] = info
|
|
|
|
k.addrToInfo[info.address] = info
|
|
|
|
k.subnetToInfo[info.subnet] = info
|
2023-03-26 16:12:45 -05:00
|
|
|
/*
|
2021-06-13 04:22:21 -05:00
|
|
|
if buf := k.addrBuffer[info.address]; buf != nil {
|
2021-09-23 04:39:12 -05:00
|
|
|
packets = append(packets, buf.packet)
|
2021-06-13 04:22:21 -05:00
|
|
|
delete(k.addrBuffer, info.address)
|
|
|
|
}
|
|
|
|
if buf := k.subnetBuffer[info.subnet]; buf != nil {
|
2021-09-23 04:39:12 -05:00
|
|
|
packets = append(packets, buf.packet)
|
2021-06-13 04:22:21 -05:00
|
|
|
delete(k.subnetBuffer, info.subnet)
|
|
|
|
}
|
2023-03-26 16:12:45 -05:00
|
|
|
*/
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
2021-09-23 04:35:31 -05:00
|
|
|
k.resetTimeout(info)
|
2021-09-23 04:39:12 -05:00
|
|
|
k.mutex.Unlock()
|
|
|
|
for _, packet := range packets {
|
2022-04-17 17:56:54 +01:00
|
|
|
_, _ = k.core.WriteTo(packet, iwt.Addr(info.key[:]))
|
2021-09-23 04:39:12 -05:00
|
|
|
}
|
2021-06-13 04:22:21 -05:00
|
|
|
return info
|
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) resetTimeout(info *keyInfo) {
|
|
|
|
if info.timeout != nil {
|
|
|
|
info.timeout.Stop()
|
|
|
|
}
|
|
|
|
info.timeout = time.AfterFunc(keyStoreTimeout, func() {
|
|
|
|
k.mutex.Lock()
|
|
|
|
defer k.mutex.Unlock()
|
|
|
|
if nfo := k.keyToInfo[info.key]; nfo == info {
|
|
|
|
delete(k.keyToInfo, info.key)
|
|
|
|
}
|
|
|
|
if nfo := k.addrToInfo[info.address]; nfo == info {
|
|
|
|
delete(k.addrToInfo, info.address)
|
|
|
|
}
|
|
|
|
if nfo := k.subnetToInfo[info.subnet]; nfo == info {
|
|
|
|
delete(k.subnetToInfo, info.subnet)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2023-03-26 16:12:45 -05:00
|
|
|
/*
|
2023-03-19 21:44:34 +00:00
|
|
|
func (k *keyStore) oobHandler(fromKey, toKey ed25519.PublicKey, data []byte) { // nolint:unused
|
2021-06-13 04:22:21 -05:00
|
|
|
if len(data) != 1+ed25519.SignatureSize {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
sig := data[1:]
|
|
|
|
switch data[0] {
|
|
|
|
case typeKeyLookup:
|
|
|
|
snet := *address.SubnetForKey(toKey)
|
|
|
|
if snet == k.subnet && ed25519.Verify(fromKey, toKey[:], sig) {
|
|
|
|
// This is looking for at least our subnet (possibly our address)
|
|
|
|
// Send a response
|
|
|
|
k.sendKeyResponse(fromKey)
|
|
|
|
}
|
|
|
|
case typeKeyResponse:
|
|
|
|
// TODO keep a list of something to match against...
|
|
|
|
// Ignore the response if it doesn't match anything of interest...
|
|
|
|
if ed25519.Verify(fromKey, toKey[:], sig) {
|
|
|
|
k.update(fromKey)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2023-03-26 16:12:45 -05:00
|
|
|
*/
|
2021-06-13 04:22:21 -05:00
|
|
|
|
|
|
|
func (k *keyStore) sendKeyLookup(partial ed25519.PublicKey) {
|
2021-07-05 13:14:12 -05:00
|
|
|
sig := ed25519.Sign(k.core.PrivateKey(), partial[:])
|
2021-06-13 04:22:21 -05:00
|
|
|
bs := append([]byte{typeKeyLookup}, sig...)
|
2023-03-19 10:33:07 +00:00
|
|
|
//_ = k.core.SendOutOfBand(partial, bs)
|
|
|
|
_ = bs
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
|
2023-03-19 21:44:34 +00:00
|
|
|
func (k *keyStore) sendKeyResponse(dest ed25519.PublicKey) { // nolint:unused
|
2021-07-05 13:14:12 -05:00
|
|
|
sig := ed25519.Sign(k.core.PrivateKey(), dest[:])
|
2021-06-13 04:22:21 -05:00
|
|
|
bs := append([]byte{typeKeyResponse}, sig...)
|
2023-03-19 10:33:07 +00:00
|
|
|
//_ = k.core.SendOutOfBand(dest, bs)
|
|
|
|
_ = bs
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) readPC(p []byte) (int, error) {
|
2021-07-05 13:14:12 -05:00
|
|
|
buf := make([]byte, k.core.MTU(), 65535)
|
2021-06-13 04:54:06 -05:00
|
|
|
for {
|
|
|
|
bs := buf
|
2021-07-05 13:14:12 -05:00
|
|
|
n, from, err := k.core.ReadFrom(bs)
|
2021-06-13 04:54:06 -05:00
|
|
|
if err != nil {
|
|
|
|
return n, err
|
|
|
|
}
|
|
|
|
if n == 0 {
|
|
|
|
continue
|
|
|
|
}
|
2021-07-05 13:14:12 -05:00
|
|
|
bs = bs[:n]
|
2021-06-13 04:54:06 -05:00
|
|
|
if len(bs) == 0 {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if bs[0]&0xf0 != 0x60 {
|
|
|
|
continue // not IPv6
|
|
|
|
}
|
|
|
|
if len(bs) < 40 {
|
|
|
|
continue
|
|
|
|
}
|
2021-06-13 13:40:20 -05:00
|
|
|
k.mutex.Lock()
|
|
|
|
mtu := int(k.mtu)
|
|
|
|
k.mutex.Unlock()
|
|
|
|
if len(bs) > mtu {
|
2021-06-13 05:25:13 -05:00
|
|
|
// Using bs would make it leak off the stack, so copy to buf
|
2022-04-03 12:48:06 +01:00
|
|
|
buf := make([]byte, 512)
|
|
|
|
cn := copy(buf, bs)
|
2021-06-13 05:25:13 -05:00
|
|
|
ptb := &icmp.PacketTooBig{
|
2021-06-13 13:40:20 -05:00
|
|
|
MTU: mtu,
|
2022-04-03 12:48:06 +01:00
|
|
|
Data: buf[:cn],
|
2021-06-13 05:25:13 -05:00
|
|
|
}
|
|
|
|
if packet, err := CreateICMPv6(buf[8:24], buf[24:40], ipv6.ICMPTypePacketTooBig, 0, ptb); err == nil {
|
|
|
|
_, _ = k.writePC(packet)
|
|
|
|
}
|
|
|
|
continue
|
|
|
|
}
|
2021-06-13 04:54:06 -05:00
|
|
|
var srcAddr, dstAddr address.Address
|
|
|
|
var srcSubnet, dstSubnet address.Subnet
|
|
|
|
copy(srcAddr[:], bs[8:])
|
|
|
|
copy(dstAddr[:], bs[24:])
|
|
|
|
copy(srcSubnet[:], bs[8:])
|
|
|
|
copy(dstSubnet[:], bs[24:])
|
|
|
|
if dstAddr != k.address && dstSubnet != k.subnet {
|
|
|
|
continue // bad local address/subnet
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
2021-06-13 04:54:06 -05:00
|
|
|
info := k.update(ed25519.PublicKey(from.(iwt.Addr)))
|
|
|
|
if srcAddr != info.address && srcSubnet != info.subnet {
|
|
|
|
continue // bad remote address/subnet
|
|
|
|
}
|
|
|
|
n = copy(p, bs)
|
|
|
|
return n, nil
|
|
|
|
}
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) writePC(bs []byte) (int, error) {
|
2021-06-13 04:54:06 -05:00
|
|
|
if bs[0]&0xf0 != 0x60 {
|
2021-06-13 04:22:21 -05:00
|
|
|
return 0, errors.New("not an IPv6 packet") // not IPv6
|
|
|
|
}
|
|
|
|
if len(bs) < 40 {
|
2021-06-25 21:15:40 -05:00
|
|
|
strErr := fmt.Sprint("undersized IPv6 packet, length: ", len(bs))
|
2021-06-13 04:54:06 -05:00
|
|
|
return 0, errors.New(strErr)
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
var srcAddr, dstAddr address.Address
|
|
|
|
var srcSubnet, dstSubnet address.Subnet
|
|
|
|
copy(srcAddr[:], bs[8:])
|
|
|
|
copy(dstAddr[:], bs[24:])
|
|
|
|
copy(srcSubnet[:], bs[8:])
|
|
|
|
copy(dstSubnet[:], bs[24:])
|
|
|
|
if srcAddr != k.address && srcSubnet != k.subnet {
|
2021-06-13 09:51:53 -05:00
|
|
|
// This happens all the time due to link-local traffic
|
|
|
|
// Don't send back an error, just drop it
|
2021-06-25 21:15:40 -05:00
|
|
|
strErr := fmt.Sprint("incorrect source address: ", net.IP(srcAddr[:]).String())
|
|
|
|
return 0, errors.New(strErr)
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
if dstAddr.IsValid() {
|
2021-07-05 13:14:12 -05:00
|
|
|
k.sendToAddress(dstAddr, bs)
|
2021-06-13 04:22:21 -05:00
|
|
|
} else if dstSubnet.IsValid() {
|
2021-07-05 13:14:12 -05:00
|
|
|
k.sendToSubnet(dstSubnet, bs)
|
2021-06-13 04:22:21 -05:00
|
|
|
} else {
|
2021-06-13 04:54:06 -05:00
|
|
|
return 0, errors.New("invalid destination address")
|
2021-06-13 04:22:21 -05:00
|
|
|
}
|
|
|
|
return len(bs), nil
|
|
|
|
}
|
2021-07-05 13:14:12 -05:00
|
|
|
|
|
|
|
// Exported API
|
|
|
|
|
|
|
|
func (k *keyStore) MaxMTU() uint64 {
|
|
|
|
return k.core.MTU()
|
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) SetMTU(mtu uint64) {
|
|
|
|
if mtu > k.MaxMTU() {
|
|
|
|
mtu = k.MaxMTU()
|
|
|
|
}
|
|
|
|
if mtu < 1280 {
|
|
|
|
mtu = 1280
|
|
|
|
}
|
|
|
|
k.mutex.Lock()
|
|
|
|
k.mtu = mtu
|
|
|
|
k.mutex.Unlock()
|
|
|
|
}
|
|
|
|
|
|
|
|
func (k *keyStore) MTU() uint64 {
|
|
|
|
k.mutex.Lock()
|
|
|
|
mtu := k.mtu
|
|
|
|
k.mutex.Unlock()
|
|
|
|
return mtu
|
|
|
|
}
|
|
|
|
|
|
|
|
type ReadWriteCloser struct {
|
|
|
|
keyStore
|
|
|
|
}
|
|
|
|
|
|
|
|
func NewReadWriteCloser(c *core.Core) *ReadWriteCloser {
|
|
|
|
rwc := new(ReadWriteCloser)
|
|
|
|
rwc.init(c)
|
|
|
|
return rwc
|
|
|
|
}
|
|
|
|
|
|
|
|
func (rwc *ReadWriteCloser) Address() address.Address {
|
|
|
|
return rwc.address
|
|
|
|
}
|
|
|
|
|
|
|
|
func (rwc *ReadWriteCloser) Subnet() address.Subnet {
|
|
|
|
return rwc.subnet
|
|
|
|
}
|
|
|
|
|
|
|
|
func (rwc *ReadWriteCloser) Read(p []byte) (n int, err error) {
|
|
|
|
return rwc.readPC(p)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (rwc *ReadWriteCloser) Write(p []byte) (n int, err error) {
|
|
|
|
return rwc.writePC(p)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (rwc *ReadWriteCloser) Close() error {
|
|
|
|
err := rwc.core.Close()
|
|
|
|
rwc.core.Stop()
|
|
|
|
return err
|
|
|
|
}
|