2019-01-02 01:55:51 +01:00
|
|
|
/* SPDX-License-Identifier: MIT
|
2018-05-03 15:04:00 +02:00
|
|
|
*
|
2021-01-28 17:52:15 +01:00
|
|
|
* Copyright (C) 2017-2021 WireGuard LLC. All Rights Reserved.
|
2018-05-03 15:04:00 +02:00
|
|
|
*/
|
|
|
|
|
2019-03-03 04:04:41 +01:00
|
|
|
package device
|
2017-05-30 22:36:49 +02:00
|
|
|
|
|
|
|
import (
|
2021-08-23 21:11:01 +02:00
|
|
|
"bytes"
|
2021-02-10 18:19:11 +01:00
|
|
|
"container/list"
|
2017-06-26 13:14:02 +02:00
|
|
|
"errors"
|
2021-08-16 20:58:15 +02:00
|
|
|
"fmt"
|
2021-08-23 21:11:01 +02:00
|
|
|
"io/ioutil"
|
2021-09-23 13:31:01 +02:00
|
|
|
"net"
|
2017-05-30 22:36:49 +02:00
|
|
|
"sync"
|
2019-06-11 18:13:52 +02:00
|
|
|
"sync/atomic"
|
2017-06-04 21:48:15 +02:00
|
|
|
"time"
|
2019-11-07 17:13:05 +01:00
|
|
|
|
2021-08-20 19:32:50 +02:00
|
|
|
"github.com/KusakabeSi/EtherGuardVPN/config"
|
2021-08-16 02:43:17 +02:00
|
|
|
"github.com/KusakabeSi/EtherGuardVPN/conn"
|
2021-10-27 03:02:44 +02:00
|
|
|
"github.com/KusakabeSi/EtherGuardVPN/path"
|
2021-08-23 21:11:01 +02:00
|
|
|
"gopkg.in/yaml.v2"
|
2017-05-30 22:36:49 +02:00
|
|
|
)
|
|
|
|
|
2021-10-27 03:02:44 +02:00
|
|
|
type endpoint_tryitem struct {
|
|
|
|
URL string
|
|
|
|
lastTry time.Time
|
|
|
|
firstTry time.Time
|
|
|
|
}
|
|
|
|
|
|
|
|
type endpoint_trylist struct {
|
|
|
|
sync.RWMutex
|
|
|
|
timeout time.Duration
|
|
|
|
peer *Peer
|
|
|
|
trymap_super map[string]*endpoint_tryitem
|
|
|
|
trymap_p2p map[string]*endpoint_tryitem
|
|
|
|
}
|
|
|
|
|
|
|
|
func NewEndpoint_trylist(peer *Peer, timeout time.Duration) *endpoint_trylist {
|
|
|
|
return &endpoint_trylist{
|
|
|
|
timeout: timeout,
|
|
|
|
peer: peer,
|
|
|
|
trymap_super: make(map[string]*endpoint_tryitem),
|
|
|
|
trymap_p2p: make(map[string]*endpoint_tryitem),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (et *endpoint_trylist) UpdateSuper(urls map[string]float64) {
|
|
|
|
et.Lock()
|
|
|
|
defer et.Unlock()
|
|
|
|
newmap_super := make(map[string]*endpoint_tryitem)
|
|
|
|
if len(urls) == 0 {
|
|
|
|
if et.peer.device.LogLevel.LogInternal {
|
|
|
|
fmt.Println(fmt.Sprintf("Internal: Peer %v : Reset trylist(super) %v", et.peer.ID.ToString(), "nil"))
|
|
|
|
}
|
|
|
|
}
|
|
|
|
for url, it := range urls {
|
|
|
|
_, err := conn.LookupIP(url, 0)
|
|
|
|
if err != nil {
|
|
|
|
if et.peer.device.LogLevel.LogInternal {
|
|
|
|
fmt.Println(fmt.Sprintf("Internal: Peer %v : Update trylist(super) %v error: %v", et.peer.ID.ToString(), url, err))
|
|
|
|
}
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if val, ok := et.trymap_super[url]; ok {
|
|
|
|
if et.peer.device.LogLevel.LogInternal {
|
|
|
|
fmt.Println(fmt.Sprintf("Internal: Peer %v : Update trylist(super) %v", et.peer.ID.ToString(), url))
|
|
|
|
}
|
|
|
|
newmap_super[url] = val
|
|
|
|
} else {
|
|
|
|
if et.peer.device.LogLevel.LogInternal {
|
|
|
|
fmt.Println(fmt.Sprintf("Internal: Peer %v : New trylist(super) %v", et.peer.ID.ToString(), url))
|
|
|
|
}
|
|
|
|
newmap_super[url] = &endpoint_tryitem{
|
|
|
|
URL: url,
|
|
|
|
lastTry: time.Time{}.Add(path.S2TD(it)),
|
|
|
|
firstTry: time.Time{},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
et.trymap_super = newmap_super
|
|
|
|
}
|
|
|
|
|
|
|
|
func (et *endpoint_trylist) UpdateP2P(url string) {
|
|
|
|
_, err := conn.LookupIP(url, 0)
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
et.Lock()
|
|
|
|
defer et.Unlock()
|
|
|
|
if _, ok := et.trymap_p2p[url]; !ok {
|
|
|
|
if et.peer.device.LogLevel.LogInternal {
|
|
|
|
fmt.Println(fmt.Sprintf("Internal: Peer %v : Add trylist(p2p) %v", et.peer.ID.ToString(), url))
|
|
|
|
}
|
|
|
|
et.trymap_p2p[url] = &endpoint_tryitem{
|
|
|
|
URL: url,
|
|
|
|
lastTry: time.Now(),
|
|
|
|
firstTry: time.Time{},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (et *endpoint_trylist) Delete(url string) {
|
|
|
|
et.Lock()
|
|
|
|
defer et.Unlock()
|
|
|
|
delete(et.trymap_super, url)
|
|
|
|
delete(et.trymap_p2p, url)
|
|
|
|
}
|
|
|
|
|
2021-10-27 03:41:13 +02:00
|
|
|
func (et *endpoint_trylist) GetNextTry() (bool, string) {
|
2021-10-27 03:02:44 +02:00
|
|
|
et.RLock()
|
|
|
|
defer et.RUnlock()
|
|
|
|
var smallest *endpoint_tryitem
|
2021-10-27 03:41:13 +02:00
|
|
|
FastTry := true
|
2021-10-27 03:02:44 +02:00
|
|
|
for _, v := range et.trymap_super {
|
|
|
|
if smallest == nil || smallest.lastTry.After(v.lastTry) {
|
|
|
|
smallest = v
|
|
|
|
}
|
|
|
|
}
|
|
|
|
for url, v := range et.trymap_p2p {
|
|
|
|
if v.firstTry.After(time.Time{}) && v.firstTry.Add(et.timeout).Before(time.Now()) {
|
|
|
|
if et.peer.device.LogLevel.LogInternal {
|
|
|
|
fmt.Println(fmt.Sprintf("Internal: Peer %v : Delete trylist(p2p) %v", et.peer.ID.ToString(), url))
|
|
|
|
}
|
|
|
|
delete(et.trymap_p2p, url)
|
|
|
|
}
|
|
|
|
if smallest.lastTry.After(v.lastTry) {
|
|
|
|
smallest = v
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if smallest == nil {
|
2021-10-27 03:41:13 +02:00
|
|
|
return false, ""
|
2021-10-27 03:02:44 +02:00
|
|
|
}
|
|
|
|
smallest.lastTry = time.Now()
|
|
|
|
if smallest.firstTry.After(time.Time{}) {
|
|
|
|
smallest.firstTry = time.Now()
|
|
|
|
}
|
2021-10-27 03:41:13 +02:00
|
|
|
if smallest.firstTry.Add(et.timeout).Before(time.Now()) {
|
|
|
|
FastTry = false
|
|
|
|
}
|
|
|
|
return FastTry, smallest.URL
|
2021-10-27 03:02:44 +02:00
|
|
|
}
|
|
|
|
|
2017-05-30 22:36:49 +02:00
|
|
|
type Peer struct {
|
2021-08-20 19:32:50 +02:00
|
|
|
isRunning AtomicBool
|
|
|
|
sync.RWMutex // Mostly protects endpoint, but is generally taken whenever we modify peer
|
|
|
|
keypairs Keypairs
|
|
|
|
handshake Handshake
|
|
|
|
device *Device
|
|
|
|
endpoint conn.Endpoint
|
2021-10-27 03:02:44 +02:00
|
|
|
endpoint_trylist *endpoint_trylist
|
2021-08-20 19:32:50 +02:00
|
|
|
LastPingReceived time.Time
|
|
|
|
stopping sync.WaitGroup // routines pending stop
|
|
|
|
|
2021-08-23 18:39:04 +02:00
|
|
|
ID config.Vertex
|
|
|
|
AskedForNeighbor bool
|
2021-08-24 10:43:55 +02:00
|
|
|
StaticConn bool //if true, this peer will not write to config file when roaming, and the endpoint will be reset periodically
|
|
|
|
ConnURL string
|
2021-09-23 13:31:01 +02:00
|
|
|
ConnAF int //0: both, 4: ipv4 only, 6: ipv6 only
|
2021-08-16 20:58:15 +02:00
|
|
|
|
2020-03-01 09:39:24 +01:00
|
|
|
// These fields are accessed with atomic operations, which must be
|
|
|
|
// 64-bit aligned even on 32-bit platforms. Go guarantees that an
|
|
|
|
// allocated struct will be 64-bit aligned. So we place
|
|
|
|
// atomically-accessed fields up front, so that they can share in
|
|
|
|
// this alignment before smaller fields throw it off.
|
2018-02-02 16:40:14 +01:00
|
|
|
stats struct {
|
2017-07-18 15:22:56 +02:00
|
|
|
txBytes uint64 // bytes send to peer (endpoint)
|
|
|
|
rxBytes uint64 // bytes received from peer
|
|
|
|
lastHandshakeNano int64 // nano seconds since epoch
|
|
|
|
}
|
2018-02-02 16:40:14 +01:00
|
|
|
|
2020-12-22 21:34:21 +01:00
|
|
|
disableRoaming bool
|
|
|
|
|
2018-05-07 22:27:03 +02:00
|
|
|
timers struct {
|
|
|
|
retransmitHandshake *Timer
|
|
|
|
sendKeepalive *Timer
|
|
|
|
newHandshake *Timer
|
|
|
|
zeroKeyMaterial *Timer
|
|
|
|
persistentKeepalive *Timer
|
2018-05-20 06:50:07 +02:00
|
|
|
handshakeAttempts uint32
|
|
|
|
needAnotherKeepalive AtomicBool
|
|
|
|
sentLastMinuteHandshake AtomicBool
|
2017-06-28 23:45:45 +02:00
|
|
|
}
|
2018-02-02 16:40:14 +01:00
|
|
|
|
2021-02-08 22:02:52 +01:00
|
|
|
state struct {
|
2021-02-09 15:35:43 +01:00
|
|
|
sync.Mutex // protects against concurrent Start/Stop
|
2021-02-08 22:02:52 +01:00
|
|
|
}
|
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
queue struct {
|
2021-01-27 18:13:53 +01:00
|
|
|
staged chan *QueueOutboundElement // staged packets before a handshake is available
|
2021-02-09 15:09:50 +01:00
|
|
|
outbound *autodrainingOutboundQueue // sequential ordering of udp transmission
|
|
|
|
inbound *autodrainingInboundQueue // sequential ordering of tun writing
|
2018-01-13 09:00:37 +01:00
|
|
|
}
|
2018-02-02 16:40:14 +01:00
|
|
|
|
2021-02-10 18:19:11 +01:00
|
|
|
cookieGenerator CookieGenerator
|
|
|
|
trieEntries list.List
|
|
|
|
persistentKeepaliveInterval uint32 // accessed atomically
|
2017-06-24 15:34:17 +02:00
|
|
|
}
|
|
|
|
|
2021-09-23 13:31:01 +02:00
|
|
|
func (device *Device) NewPeer(pk NoisePublicKey, id config.Vertex, isSuper bool) (*Peer, error) {
|
|
|
|
if isSuper == false {
|
|
|
|
if id < config.Special_NodeID {
|
2021-09-21 22:03:11 +02:00
|
|
|
//pass check
|
|
|
|
} else {
|
2021-09-23 13:31:01 +02:00
|
|
|
return nil, errors.New(fmt.Sprint("ID ", uint32(id), " is a special NodeID"))
|
2021-09-21 22:03:11 +02:00
|
|
|
}
|
|
|
|
} else {
|
2021-09-23 13:31:01 +02:00
|
|
|
if id == config.SuperNodeMessage {
|
2021-09-21 22:03:11 +02:00
|
|
|
//pass check
|
|
|
|
} else {
|
2021-09-23 13:31:01 +02:00
|
|
|
return nil, errors.New(fmt.Sprint("ID", uint32(id), "is not a supernode NodeID"))
|
2021-09-21 22:03:11 +02:00
|
|
|
}
|
|
|
|
}
|
2021-09-23 13:31:01 +02:00
|
|
|
|
2021-01-19 18:02:16 +01:00
|
|
|
if device.isClosed() {
|
2018-05-13 19:33:41 +02:00
|
|
|
return nil, errors.New("device closed")
|
2018-01-26 22:52:32 +01:00
|
|
|
}
|
|
|
|
|
2018-02-02 16:40:14 +01:00
|
|
|
// lock resources
|
2019-01-03 19:04:00 +01:00
|
|
|
device.staticIdentity.RLock()
|
|
|
|
defer device.staticIdentity.RUnlock()
|
2018-02-02 16:40:14 +01:00
|
|
|
|
2019-01-03 19:04:00 +01:00
|
|
|
device.peers.Lock()
|
|
|
|
defer device.peers.Unlock()
|
2018-02-02 16:40:14 +01:00
|
|
|
|
|
|
|
// check if over limit
|
|
|
|
if len(device.peers.keyMap) >= MaxPeers {
|
2018-05-13 19:33:41 +02:00
|
|
|
return nil, errors.New("too many peers")
|
2018-02-02 16:40:14 +01:00
|
|
|
}
|
2018-01-26 22:52:32 +01:00
|
|
|
|
2017-06-26 13:14:02 +02:00
|
|
|
// create peer
|
2021-10-27 03:02:44 +02:00
|
|
|
if device.LogLevel.LogInternal {
|
|
|
|
fmt.Println("Internal: Create peer with ID : " + id.ToString() + " and PubKey:" + pk.ToString())
|
2021-08-21 16:54:24 +02:00
|
|
|
}
|
2017-06-30 14:41:08 +02:00
|
|
|
peer := new(Peer)
|
2019-01-03 19:04:00 +01:00
|
|
|
peer.Lock()
|
|
|
|
defer peer.Unlock()
|
2017-07-01 23:29:22 +02:00
|
|
|
|
2018-05-13 23:14:43 +02:00
|
|
|
peer.cookieGenerator.Init(pk)
|
2017-07-01 23:29:22 +02:00
|
|
|
peer.device = device
|
2021-10-27 03:02:44 +02:00
|
|
|
peer.endpoint_trylist = NewEndpoint_trylist(peer, path.S2TD(device.DRoute.PeerAliveTimeout))
|
2021-02-10 00:21:12 +01:00
|
|
|
peer.queue.outbound = newAutodrainingOutboundQueue(device)
|
|
|
|
peer.queue.inbound = newAutodrainingInboundQueue(device)
|
|
|
|
peer.queue.staged = make(chan *QueueOutboundElement, QueueStagedSize)
|
2017-06-30 14:41:08 +02:00
|
|
|
// map public key
|
2018-02-02 16:40:14 +01:00
|
|
|
_, ok := device.peers.keyMap[pk]
|
2017-06-26 13:14:02 +02:00
|
|
|
if ok {
|
2021-11-06 10:14:13 +01:00
|
|
|
return nil, fmt.Errorf("adding existing peer pubkey: %v", pk.ToString())
|
2021-08-16 20:58:15 +02:00
|
|
|
}
|
|
|
|
_, ok = device.peers.IDMap[id]
|
|
|
|
if ok {
|
2021-11-06 10:14:13 +01:00
|
|
|
return nil, fmt.Errorf("adding existing peer id: %v", id)
|
2017-06-26 13:14:02 +02:00
|
|
|
}
|
2021-08-16 20:58:15 +02:00
|
|
|
peer.ID = id
|
2017-06-24 15:34:17 +02:00
|
|
|
|
2018-02-02 17:24:29 +01:00
|
|
|
// pre-compute DH
|
2017-06-26 13:14:02 +02:00
|
|
|
handshake := &peer.handshake
|
|
|
|
handshake.mutex.Lock()
|
2018-05-13 23:14:43 +02:00
|
|
|
handshake.precomputedStaticStatic = device.staticIdentity.privateKey.sharedSecret(pk)
|
2019-08-05 16:57:41 +02:00
|
|
|
handshake.remoteStatic = pk
|
2017-06-26 13:14:02 +02:00
|
|
|
handshake.mutex.Unlock()
|
2017-06-24 15:34:17 +02:00
|
|
|
|
2017-10-16 21:33:47 +02:00
|
|
|
// reset endpoint
|
2017-11-18 23:34:02 +01:00
|
|
|
peer.endpoint = nil
|
2017-10-16 21:33:47 +02:00
|
|
|
|
2020-03-18 06:06:56 +01:00
|
|
|
// add
|
2021-08-25 10:13:53 +02:00
|
|
|
if id == config.SuperNodeMessage { // To communicate with supernode
|
2021-08-20 19:32:50 +02:00
|
|
|
device.peers.SuperPeer[pk] = peer
|
2021-08-21 16:54:24 +02:00
|
|
|
device.peers.keyMap[pk] = peer
|
2021-08-20 19:32:50 +02:00
|
|
|
} else { // Regular peer, other edgenodes
|
|
|
|
device.peers.keyMap[pk] = peer
|
|
|
|
device.peers.IDMap[id] = peer
|
|
|
|
}
|
2019-08-05 16:57:41 +02:00
|
|
|
|
2018-01-26 22:52:32 +01:00
|
|
|
// start peer
|
2021-02-08 19:01:35 +01:00
|
|
|
peer.timersInit()
|
2021-01-19 18:02:16 +01:00
|
|
|
if peer.device.isUp() {
|
2018-01-26 22:52:32 +01:00
|
|
|
peer.Start()
|
|
|
|
}
|
|
|
|
|
2017-08-07 15:25:04 +02:00
|
|
|
return peer, nil
|
2017-05-30 22:36:49 +02:00
|
|
|
}
|
2017-06-28 23:45:45 +02:00
|
|
|
|
2021-10-27 03:02:44 +02:00
|
|
|
func (peer *Peer) IsPeerAlive() bool {
|
|
|
|
PeerAliveTimeout := path.S2TD(peer.device.DRoute.PeerAliveTimeout)
|
|
|
|
if peer.endpoint == nil {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
if peer.LastPingReceived.Add(PeerAliveTimeout).Before(time.Now()) {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2017-10-27 10:43:37 +02:00
|
|
|
func (peer *Peer) SendBuffer(buffer []byte) error {
|
2019-01-03 19:04:00 +01:00
|
|
|
peer.device.net.RLock()
|
|
|
|
defer peer.device.net.RUnlock()
|
2017-12-29 17:42:09 +01:00
|
|
|
|
2021-02-22 02:01:50 +01:00
|
|
|
if peer.device.isClosed() {
|
|
|
|
return nil
|
2018-02-02 20:45:25 +01:00
|
|
|
}
|
|
|
|
|
2019-01-03 19:04:00 +01:00
|
|
|
peer.RLock()
|
|
|
|
defer peer.RUnlock()
|
2017-12-29 17:42:09 +01:00
|
|
|
|
2017-11-18 23:34:02 +01:00
|
|
|
if peer.endpoint == nil {
|
2018-05-13 19:33:41 +02:00
|
|
|
return errors.New("no known endpoint for peer")
|
2017-10-27 10:43:37 +02:00
|
|
|
}
|
2017-12-29 17:42:09 +01:00
|
|
|
|
2019-06-11 18:13:52 +02:00
|
|
|
err := peer.device.net.bind.Send(buffer, peer.endpoint)
|
|
|
|
if err == nil {
|
|
|
|
atomic.AddUint64(&peer.stats.txBytes, uint64(len(buffer)))
|
|
|
|
}
|
|
|
|
return err
|
2017-10-27 10:43:37 +02:00
|
|
|
}
|
|
|
|
|
2017-07-13 14:32:40 +02:00
|
|
|
func (peer *Peer) String() string {
|
2021-05-14 00:30:18 +02:00
|
|
|
// The awful goo that follows is identical to:
|
|
|
|
//
|
|
|
|
// base64Key := base64.StdEncoding.EncodeToString(peer.handshake.remoteStatic[:])
|
|
|
|
// abbreviatedKey := base64Key[0:4] + "…" + base64Key[39:43]
|
|
|
|
// return fmt.Sprintf("peer(%s)", abbreviatedKey)
|
|
|
|
//
|
|
|
|
// except that it is considerably more efficient.
|
2021-05-14 01:07:55 +02:00
|
|
|
src := peer.handshake.remoteStatic
|
|
|
|
b64 := func(input byte) byte {
|
|
|
|
return input + 'A' + byte(((25-int(input))>>8)&6) - byte(((51-int(input))>>8)&75) - byte(((61-int(input))>>8)&15) + byte(((62-int(input))>>8)&3)
|
|
|
|
}
|
|
|
|
b := []byte("peer(____…____)")
|
|
|
|
const first = len("peer(")
|
|
|
|
const second = len("peer(____…")
|
|
|
|
b[first+0] = b64((src[0] >> 2) & 63)
|
|
|
|
b[first+1] = b64(((src[0] << 4) | (src[1] >> 4)) & 63)
|
|
|
|
b[first+2] = b64(((src[1] << 2) | (src[2] >> 6)) & 63)
|
|
|
|
b[first+3] = b64(src[2] & 63)
|
|
|
|
b[second+0] = b64(src[29] & 63)
|
|
|
|
b[second+1] = b64((src[30] >> 2) & 63)
|
|
|
|
b[second+2] = b64(((src[30] << 4) | (src[31] >> 4)) & 63)
|
|
|
|
b[second+3] = b64((src[31] << 2) & 63)
|
|
|
|
return string(b)
|
2017-07-13 14:32:40 +02:00
|
|
|
}
|
|
|
|
|
2018-01-13 09:00:37 +01:00
|
|
|
func (peer *Peer) Start() {
|
2018-02-02 17:24:29 +01:00
|
|
|
// should never start a peer on a closed device
|
2021-01-19 18:02:16 +01:00
|
|
|
if peer.device.isClosed() {
|
2018-02-02 16:40:14 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2018-02-02 17:24:29 +01:00
|
|
|
// prevent simultaneous start/stop operations
|
2021-02-09 15:35:43 +01:00
|
|
|
peer.state.Lock()
|
|
|
|
defer peer.state.Unlock()
|
2018-02-02 20:45:25 +01:00
|
|
|
|
|
|
|
if peer.isRunning.Get() {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2018-02-04 19:18:44 +01:00
|
|
|
device := peer.device
|
2021-05-07 12:17:41 +02:00
|
|
|
device.log.Verbosef("%v - Starting", peer)
|
2018-01-26 22:52:32 +01:00
|
|
|
|
2018-05-05 22:07:58 +02:00
|
|
|
// reset routine state
|
2021-01-29 14:54:11 +01:00
|
|
|
peer.stopping.Wait()
|
|
|
|
peer.stopping.Add(2)
|
2017-12-29 17:42:09 +01:00
|
|
|
|
2021-02-03 17:52:31 +01:00
|
|
|
peer.handshake.mutex.Lock()
|
|
|
|
peer.handshake.lastSentHandshake = time.Now().Add(-(RekeyTimeout + time.Second))
|
|
|
|
peer.handshake.mutex.Unlock()
|
|
|
|
|
2021-02-02 19:46:34 +01:00
|
|
|
peer.device.queue.encryption.wg.Add(1) // keep encryption queue open for our writes
|
2018-01-26 22:52:32 +01:00
|
|
|
|
2021-02-08 19:01:35 +01:00
|
|
|
peer.timersStart()
|
2018-02-02 20:45:25 +01:00
|
|
|
|
2021-02-10 00:39:28 +01:00
|
|
|
device.flushInboundQueue(peer.queue.inbound)
|
|
|
|
device.flushOutboundQueue(peer.queue.outbound)
|
2017-12-29 17:42:09 +01:00
|
|
|
go peer.RoutineSequentialSender()
|
|
|
|
go peer.RoutineSequentialReceiver()
|
|
|
|
|
2018-01-26 22:52:32 +01:00
|
|
|
peer.isRunning.Set(true)
|
2017-12-29 17:42:09 +01:00
|
|
|
}
|
|
|
|
|
2018-05-13 23:14:43 +02:00
|
|
|
func (peer *Peer) ZeroAndFlushAll() {
|
|
|
|
device := peer.device
|
|
|
|
|
|
|
|
// clear key pairs
|
|
|
|
|
|
|
|
keypairs := &peer.keypairs
|
2019-01-03 19:04:00 +01:00
|
|
|
keypairs.Lock()
|
2018-05-13 23:14:43 +02:00
|
|
|
device.DeleteKeypair(keypairs.previous)
|
|
|
|
device.DeleteKeypair(keypairs.current)
|
2020-05-02 09:30:23 +02:00
|
|
|
device.DeleteKeypair(keypairs.loadNext())
|
2018-05-13 23:14:43 +02:00
|
|
|
keypairs.previous = nil
|
|
|
|
keypairs.current = nil
|
2020-05-02 09:30:23 +02:00
|
|
|
keypairs.storeNext(nil)
|
2019-01-03 19:04:00 +01:00
|
|
|
keypairs.Unlock()
|
2018-05-13 23:14:43 +02:00
|
|
|
|
|
|
|
// clear handshake state
|
|
|
|
|
|
|
|
handshake := &peer.handshake
|
|
|
|
handshake.mutex.Lock()
|
|
|
|
device.indexTable.Delete(handshake.localIndex)
|
|
|
|
handshake.Clear()
|
|
|
|
handshake.mutex.Unlock()
|
|
|
|
|
2021-01-27 18:13:53 +01:00
|
|
|
peer.FlushStagedPackets()
|
2018-05-13 23:14:43 +02:00
|
|
|
}
|
|
|
|
|
2019-07-11 17:36:36 +02:00
|
|
|
func (peer *Peer) ExpireCurrentKeypairs() {
|
|
|
|
handshake := &peer.handshake
|
|
|
|
handshake.mutex.Lock()
|
|
|
|
peer.device.indexTable.Delete(handshake.localIndex)
|
|
|
|
handshake.Clear()
|
|
|
|
peer.handshake.lastSentHandshake = time.Now().Add(-(RekeyTimeout + time.Second))
|
2020-12-16 00:02:13 +01:00
|
|
|
handshake.mutex.Unlock()
|
2019-07-11 17:36:36 +02:00
|
|
|
|
|
|
|
keypairs := &peer.keypairs
|
|
|
|
keypairs.Lock()
|
|
|
|
if keypairs.current != nil {
|
2020-12-16 00:02:13 +01:00
|
|
|
atomic.StoreUint64(&keypairs.current.sendNonce, RejectAfterMessages)
|
2019-07-11 17:36:36 +02:00
|
|
|
}
|
|
|
|
if keypairs.next != nil {
|
2020-12-16 00:02:13 +01:00
|
|
|
next := keypairs.loadNext()
|
|
|
|
atomic.StoreUint64(&next.sendNonce, RejectAfterMessages)
|
2019-07-11 17:36:36 +02:00
|
|
|
}
|
|
|
|
keypairs.Unlock()
|
|
|
|
}
|
|
|
|
|
2017-12-29 17:42:09 +01:00
|
|
|
func (peer *Peer) Stop() {
|
2021-02-09 15:35:43 +01:00
|
|
|
peer.state.Lock()
|
|
|
|
defer peer.state.Unlock()
|
2018-02-02 17:24:29 +01:00
|
|
|
|
2018-02-02 20:45:25 +01:00
|
|
|
if !peer.isRunning.Swap(false) {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-05-07 12:17:41 +02:00
|
|
|
peer.device.log.Verbosef("%v - Stopping", peer)
|
2018-01-26 22:52:32 +01:00
|
|
|
|
2018-05-07 22:27:03 +02:00
|
|
|
peer.timersStop()
|
2021-02-08 22:02:52 +01:00
|
|
|
// Signal that RoutineSequentialSender and RoutineSequentialReceiver should exit.
|
2021-02-09 15:09:50 +01:00
|
|
|
peer.queue.inbound.c <- nil
|
|
|
|
peer.queue.outbound.c <- nil
|
2021-01-29 14:54:11 +01:00
|
|
|
peer.stopping.Wait()
|
2021-02-02 19:46:34 +01:00
|
|
|
peer.device.queue.encryption.wg.Done() // no more writes to encryption queue from us
|
2018-01-26 22:52:32 +01:00
|
|
|
|
2018-05-13 23:14:43 +02:00
|
|
|
peer.ZeroAndFlushAll()
|
2017-06-28 23:45:45 +02:00
|
|
|
}
|
2018-05-26 02:59:26 +02:00
|
|
|
|
2021-08-21 16:54:24 +02:00
|
|
|
func (peer *Peer) SetPSK(psk NoisePresharedKey) {
|
2021-09-23 13:31:01 +02:00
|
|
|
if peer.device.IsSuperNode == false && peer.ID < config.Special_NodeID && peer.device.DRoute.P2P.UseP2P == true {
|
|
|
|
peer.device.log.Verbosef("Preshared keys disabled in P2P mode.")
|
|
|
|
return
|
|
|
|
}
|
2021-08-21 16:54:24 +02:00
|
|
|
peer.handshake.mutex.Lock()
|
|
|
|
peer.handshake.presharedKey = psk
|
|
|
|
peer.handshake.mutex.Unlock()
|
|
|
|
}
|
|
|
|
|
2021-09-23 13:31:01 +02:00
|
|
|
func (peer *Peer) SetEndpointFromConnURL(connurl string, af int, static bool) error {
|
|
|
|
peer.StaticConn = static
|
|
|
|
peer.ConnURL = connurl
|
|
|
|
peer.ConnAF = af
|
|
|
|
|
2021-10-27 03:02:44 +02:00
|
|
|
if peer.device.LogLevel.LogInternal {
|
|
|
|
fmt.Println("Internal: Set endpoint to " + connurl + " for NodeID:" + peer.ID.ToString())
|
|
|
|
}
|
2021-09-23 13:31:01 +02:00
|
|
|
var err error
|
|
|
|
connurl, err = conn.LookupIP(connurl, af)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
endpoint, err := peer.device.net.bind.ParseEndpoint(connurl)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
peer.StaticConn = static
|
|
|
|
peer.ConnURL = connurl
|
|
|
|
peer.SetEndpointFromPacket(endpoint)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-11-07 17:13:05 +01:00
|
|
|
func (peer *Peer) SetEndpointFromPacket(endpoint conn.Endpoint) {
|
2020-10-07 10:17:48 +02:00
|
|
|
if peer.disableRoaming {
|
2018-05-26 02:59:26 +02:00
|
|
|
return
|
|
|
|
}
|
2019-01-03 19:04:00 +01:00
|
|
|
peer.Lock()
|
2021-09-23 13:31:01 +02:00
|
|
|
if peer.ID == config.SuperNodeMessage {
|
|
|
|
conn, err := net.Dial("udp", endpoint.DstToString())
|
|
|
|
defer conn.Close()
|
|
|
|
if err == nil {
|
|
|
|
IP := conn.LocalAddr().(*net.UDPAddr).IP
|
|
|
|
if ip4 := IP.To4(); ip4 != nil {
|
|
|
|
peer.device.peers.LocalV4 = ip4
|
|
|
|
} else {
|
|
|
|
peer.device.peers.LocalV6 = IP
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2021-08-23 21:11:01 +02:00
|
|
|
peer.device.SaveToConfig(peer, endpoint)
|
2018-05-26 02:59:26 +02:00
|
|
|
peer.endpoint = endpoint
|
2019-01-03 19:04:00 +01:00
|
|
|
peer.Unlock()
|
2018-05-26 02:59:26 +02:00
|
|
|
}
|
2021-08-20 19:32:50 +02:00
|
|
|
|
|
|
|
func (peer *Peer) GetEndpointSrcStr() string {
|
2021-08-21 16:54:24 +02:00
|
|
|
if peer.endpoint == nil {
|
|
|
|
return ""
|
|
|
|
}
|
2021-08-20 19:32:50 +02:00
|
|
|
return peer.endpoint.SrcToString()
|
|
|
|
}
|
|
|
|
|
|
|
|
func (peer *Peer) GetEndpointDstStr() string {
|
2021-08-21 16:54:24 +02:00
|
|
|
if peer.endpoint == nil {
|
|
|
|
return ""
|
|
|
|
}
|
2021-08-20 19:32:50 +02:00
|
|
|
return peer.endpoint.DstToString()
|
|
|
|
}
|
2021-08-23 21:11:01 +02:00
|
|
|
|
|
|
|
func (device *Device) SaveToConfig(peer *Peer, endpoint conn.Endpoint) {
|
2021-09-21 22:03:11 +02:00
|
|
|
if device.IsSuperNode { //Can't use in super mode
|
2021-08-23 21:11:01 +02:00
|
|
|
return
|
|
|
|
}
|
2021-08-24 10:43:55 +02:00
|
|
|
if peer.StaticConn == true { //static conn do not write new endpoint to config
|
2021-08-23 21:11:01 +02:00
|
|
|
return
|
|
|
|
}
|
2021-08-24 10:43:55 +02:00
|
|
|
if !device.DRoute.P2P.UseP2P { //Must in p2p mode
|
2021-08-23 21:11:01 +02:00
|
|
|
return
|
|
|
|
}
|
2021-08-24 10:43:55 +02:00
|
|
|
if peer.endpoint != nil && peer.endpoint.DstIP().Equal(endpoint.DstIP()) { //endpoint changed
|
2021-08-23 21:11:01 +02:00
|
|
|
return
|
|
|
|
}
|
2021-08-24 10:43:55 +02:00
|
|
|
|
2021-08-23 21:11:01 +02:00
|
|
|
url := endpoint.DstToString()
|
|
|
|
foundInFile := false
|
2021-09-21 03:15:23 +02:00
|
|
|
pubkeystr := peer.handshake.remoteStatic.ToString()
|
|
|
|
pskstr := peer.handshake.presharedKey.ToString()
|
2021-08-23 21:11:01 +02:00
|
|
|
if bytes.Equal(peer.handshake.presharedKey[:], make([]byte, 32)) {
|
|
|
|
pskstr = ""
|
|
|
|
}
|
|
|
|
for _, peerfile := range device.EdgeConfig.Peers {
|
|
|
|
if peerfile.NodeID == peer.ID && peerfile.PubKey == pubkeystr {
|
|
|
|
foundInFile = true
|
|
|
|
if peerfile.Static == false {
|
|
|
|
peerfile.EndPoint = url
|
|
|
|
}
|
|
|
|
} else if peerfile.NodeID == peer.ID || peerfile.PubKey == pubkeystr {
|
2021-08-25 10:13:53 +02:00
|
|
|
panic("Found NodeID match " + peer.ID.ToString() + ", but PubKey Not match %s enrties in config file" + pubkeystr)
|
2021-08-23 21:11:01 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
if !foundInFile {
|
|
|
|
device.EdgeConfig.Peers = append(device.EdgeConfig.Peers, config.PeerInfo{
|
|
|
|
NodeID: peer.ID,
|
|
|
|
PubKey: pubkeystr,
|
|
|
|
PSKey: pskstr,
|
|
|
|
EndPoint: url,
|
|
|
|
Static: false,
|
|
|
|
})
|
|
|
|
}
|
|
|
|
go device.SaveConfig()
|
|
|
|
}
|
|
|
|
|
|
|
|
func (device *Device) SaveConfig() {
|
|
|
|
if device.DRoute.SaveNewPeers {
|
|
|
|
configbytes, _ := yaml.Marshal(device.EdgeConfig)
|
2021-09-21 22:03:11 +02:00
|
|
|
ioutil.WriteFile(device.EdgeConfigPath, configbytes, 0644)
|
2021-08-23 21:11:01 +02:00
|
|
|
}
|
|
|
|
}
|