2017-06-26 13:14:02 +02:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
2017-06-26 22:07:29 +02:00
|
|
|
"encoding/binary"
|
|
|
|
"golang.org/x/crypto/chacha20poly1305"
|
2017-07-13 14:32:40 +02:00
|
|
|
"golang.org/x/net/ipv4"
|
|
|
|
"golang.org/x/net/ipv6"
|
2017-06-26 13:14:02 +02:00
|
|
|
"net"
|
|
|
|
"sync"
|
2017-06-30 14:41:08 +02:00
|
|
|
"sync/atomic"
|
|
|
|
"time"
|
2017-06-26 13:14:02 +02:00
|
|
|
)
|
|
|
|
|
2017-12-01 23:37:26 +01:00
|
|
|
/* Outbound flow
|
2017-06-26 13:14:02 +02:00
|
|
|
*
|
|
|
|
* 1. TUN queue
|
2017-06-28 23:45:45 +02:00
|
|
|
* 2. Routing (sequential)
|
|
|
|
* 3. Nonce assignment (sequential)
|
|
|
|
* 4. Encryption (parallel)
|
|
|
|
* 5. Transmission (sequential)
|
2017-06-26 13:14:02 +02:00
|
|
|
*
|
2017-12-01 23:37:26 +01:00
|
|
|
* The functions in this file occur (roughly) in the order in
|
|
|
|
* which the packets are processed.
|
|
|
|
*
|
|
|
|
* Locking, Producers and Consumers
|
|
|
|
*
|
|
|
|
* The order of packets (per peer) must be maintained,
|
|
|
|
* but encryption of packets happen out-of-order:
|
|
|
|
*
|
|
|
|
* The sequential consumers will attempt to take the lock,
|
2017-07-13 14:32:40 +02:00
|
|
|
* workers release lock when they have completed work (encryption) on the packet.
|
2017-07-06 15:43:55 +02:00
|
|
|
*
|
|
|
|
* If the element is inserted into the "encryption queue",
|
2017-12-01 23:37:26 +01:00
|
|
|
* the content is preceded by enough "junk" to contain the transport header
|
2017-07-07 13:47:09 +02:00
|
|
|
* (to allow the construction of transport messages in-place)
|
2017-06-28 23:45:45 +02:00
|
|
|
*/
|
2017-12-01 23:37:26 +01:00
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
type QueueOutboundElement struct {
|
2017-07-08 23:51:26 +02:00
|
|
|
dropped int32
|
2017-06-28 23:45:45 +02:00
|
|
|
mutex sync.Mutex
|
2017-07-14 14:25:18 +02:00
|
|
|
buffer *[MaxMessageSize]byte // slice holding the packet data
|
2017-09-09 15:03:01 +02:00
|
|
|
packet []byte // slice of "buffer" (always!)
|
2017-07-14 14:25:18 +02:00
|
|
|
nonce uint64 // nonce for encryption
|
|
|
|
keyPair *KeyPair // key-pair for encryption
|
|
|
|
peer *Peer // related peer
|
2017-06-26 13:14:02 +02:00
|
|
|
}
|
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
func (peer *Peer) FlushNonceQueue() {
|
|
|
|
elems := len(peer.queue.nonce)
|
2017-07-13 14:32:40 +02:00
|
|
|
for i := 0; i < elems; i++ {
|
2017-06-28 23:45:45 +02:00
|
|
|
select {
|
|
|
|
case <-peer.queue.nonce:
|
|
|
|
default:
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
2017-06-27 17:33:06 +02:00
|
|
|
}
|
|
|
|
|
2017-07-06 15:43:55 +02:00
|
|
|
func (device *Device) NewOutboundElement() *QueueOutboundElement {
|
2017-07-14 14:25:18 +02:00
|
|
|
return &QueueOutboundElement{
|
|
|
|
dropped: AtomicFalse,
|
|
|
|
buffer: device.pool.messageBuffers.Get().(*[MaxMessageSize]byte),
|
|
|
|
}
|
2017-07-06 15:43:55 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func (elem *QueueOutboundElement) Drop() {
|
2017-07-08 23:51:26 +02:00
|
|
|
atomic.StoreInt32(&elem.dropped, AtomicTrue)
|
2017-07-06 15:43:55 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func (elem *QueueOutboundElement) IsDropped() bool {
|
2017-07-08 23:51:26 +02:00
|
|
|
return atomic.LoadInt32(&elem.dropped) == AtomicTrue
|
2017-07-06 15:43:55 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func addToOutboundQueue(
|
|
|
|
queue chan *QueueOutboundElement,
|
|
|
|
element *QueueOutboundElement,
|
|
|
|
) {
|
2017-06-28 23:45:45 +02:00
|
|
|
for {
|
|
|
|
select {
|
2017-07-06 15:43:55 +02:00
|
|
|
case queue <- element:
|
2017-06-30 14:41:08 +02:00
|
|
|
return
|
2017-06-28 23:45:45 +02:00
|
|
|
default:
|
|
|
|
select {
|
2017-07-06 15:43:55 +02:00
|
|
|
case old := <-queue:
|
|
|
|
old.Drop()
|
2017-06-28 23:45:45 +02:00
|
|
|
default:
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-07-08 23:51:26 +02:00
|
|
|
func addToEncryptionQueue(
|
|
|
|
queue chan *QueueOutboundElement,
|
|
|
|
element *QueueOutboundElement,
|
|
|
|
) {
|
|
|
|
for {
|
|
|
|
select {
|
|
|
|
case queue <- element:
|
|
|
|
return
|
|
|
|
default:
|
|
|
|
select {
|
|
|
|
case old := <-queue:
|
2017-08-25 14:53:23 +02:00
|
|
|
// drop & release to potential consumer
|
2017-07-08 23:51:26 +02:00
|
|
|
old.Drop()
|
|
|
|
old.mutex.Unlock()
|
|
|
|
default:
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
/* Reads packets from the TUN and inserts
|
|
|
|
* into nonce queue for peer
|
|
|
|
*
|
|
|
|
* Obs. Single instance per TUN device
|
|
|
|
*/
|
2017-08-04 16:15:53 +02:00
|
|
|
func (device *Device) RoutineReadFromTUN() {
|
2017-07-13 14:32:40 +02:00
|
|
|
|
2017-08-25 14:53:23 +02:00
|
|
|
elem := device.NewOutboundElement()
|
2017-07-06 15:43:55 +02:00
|
|
|
|
2017-07-13 14:32:40 +02:00
|
|
|
logDebug := device.log.Debug
|
|
|
|
logError := device.log.Error
|
|
|
|
|
2017-08-25 14:53:23 +02:00
|
|
|
logDebug.Println("Routine, TUN Reader started")
|
2017-07-13 14:32:40 +02:00
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
for {
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-08-25 14:53:23 +02:00
|
|
|
// read packet
|
2017-07-06 15:43:55 +02:00
|
|
|
|
2017-07-14 14:25:18 +02:00
|
|
|
elem.packet = elem.buffer[MessageTransportHeaderSize:]
|
2017-08-11 16:18:20 +02:00
|
|
|
size, err := device.tun.device.Read(elem.packet)
|
2017-06-28 23:45:45 +02:00
|
|
|
if err != nil {
|
2017-07-13 14:32:40 +02:00
|
|
|
logError.Println("Failed to read packet from TUN device:", err)
|
|
|
|
device.Close()
|
|
|
|
return
|
2017-06-28 23:45:45 +02:00
|
|
|
}
|
2017-07-13 14:32:40 +02:00
|
|
|
|
2017-08-25 14:53:23 +02:00
|
|
|
if size == 0 || size > MaxContentSize {
|
2017-06-28 23:45:45 +02:00
|
|
|
continue
|
|
|
|
}
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-08-04 16:15:53 +02:00
|
|
|
elem.packet = elem.packet[:size]
|
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
// lookup peer
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
var peer *Peer
|
2017-07-06 15:43:55 +02:00
|
|
|
switch elem.packet[0] >> 4 {
|
2017-07-13 14:32:40 +02:00
|
|
|
case ipv4.Version:
|
2017-08-04 16:15:53 +02:00
|
|
|
if len(elem.packet) < ipv4.HeaderLen {
|
|
|
|
continue
|
|
|
|
}
|
2017-07-06 15:43:55 +02:00
|
|
|
dst := elem.packet[IPv4offsetDst : IPv4offsetDst+net.IPv4len]
|
2017-06-28 23:45:45 +02:00
|
|
|
peer = device.routingTable.LookupIPv4(dst)
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-07-13 14:32:40 +02:00
|
|
|
case ipv6.Version:
|
2017-08-04 16:15:53 +02:00
|
|
|
if len(elem.packet) < ipv6.HeaderLen {
|
|
|
|
continue
|
|
|
|
}
|
2017-07-06 15:43:55 +02:00
|
|
|
dst := elem.packet[IPv6offsetDst : IPv6offsetDst+net.IPv6len]
|
2017-06-28 23:45:45 +02:00
|
|
|
peer = device.routingTable.LookupIPv6(dst)
|
2017-06-26 13:14:02 +02:00
|
|
|
|
|
|
|
default:
|
2017-12-01 23:37:26 +01:00
|
|
|
logDebug.Println("Received packet with unknown IP version")
|
2017-06-28 23:45:45 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
if peer == nil {
|
2017-06-29 14:39:21 +02:00
|
|
|
continue
|
2017-06-28 23:45:45 +02:00
|
|
|
}
|
2017-07-13 14:32:40 +02:00
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
// insert into nonce/pre-handshake queue
|
|
|
|
|
2017-11-30 23:22:40 +01:00
|
|
|
peer.timer.handshakeDeadline.Reset(RekeyAttemptTime)
|
2017-07-06 15:43:55 +02:00
|
|
|
addToOutboundQueue(peer.queue.nonce, elem)
|
2017-08-25 14:53:23 +02:00
|
|
|
elem = device.NewOutboundElement()
|
2017-06-26 13:14:02 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
/* Queues packets when there is no handshake.
|
|
|
|
* Then assigns nonces to packets sequentially
|
|
|
|
* and creates "work" structs for workers
|
2017-06-26 13:14:02 +02:00
|
|
|
*
|
2017-06-28 23:45:45 +02:00
|
|
|
* Obs. A single instance per peer
|
2017-06-26 13:14:02 +02:00
|
|
|
*/
|
2017-06-28 23:45:45 +02:00
|
|
|
func (peer *Peer) RoutineNonce() {
|
2017-06-26 22:07:29 +02:00
|
|
|
var keyPair *KeyPair
|
|
|
|
|
2017-06-30 14:41:08 +02:00
|
|
|
device := peer.device
|
2017-07-07 13:47:09 +02:00
|
|
|
logDebug := device.log.Debug
|
2017-07-13 14:32:40 +02:00
|
|
|
logDebug.Println("Routine, nonce worker, started for peer", peer.String())
|
2017-06-26 22:07:29 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
for {
|
|
|
|
NextPacket:
|
|
|
|
select {
|
2017-11-30 23:22:40 +01:00
|
|
|
case <-peer.signal.stop.Wait():
|
2017-09-09 15:03:01 +02:00
|
|
|
return
|
2017-06-30 14:41:08 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
case elem := <-peer.queue.nonce:
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-06-30 14:41:08 +02:00
|
|
|
// wait for key pair
|
|
|
|
|
|
|
|
for {
|
2017-06-26 22:07:29 +02:00
|
|
|
keyPair = peer.keyPairs.Current()
|
2017-06-30 14:41:08 +02:00
|
|
|
if keyPair != nil && keyPair.sendNonce < RejectAfterMessages {
|
|
|
|
if time.Now().Sub(keyPair.created) < RejectAfterTime {
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
2017-09-09 15:03:01 +02:00
|
|
|
|
2017-11-30 23:22:40 +01:00
|
|
|
peer.signal.handshakeBegin.Send()
|
|
|
|
|
2017-07-13 14:32:40 +02:00
|
|
|
logDebug.Println("Awaiting key-pair for", peer.String())
|
2017-06-26 22:07:29 +02:00
|
|
|
|
2017-06-30 14:41:08 +02:00
|
|
|
select {
|
2017-11-30 23:22:40 +01:00
|
|
|
case <-peer.signal.newKeyPair.Wait():
|
|
|
|
case <-peer.signal.flushNonceQueue.Wait():
|
2017-07-13 14:32:40 +02:00
|
|
|
logDebug.Println("Clearing queue for", peer.String())
|
2017-06-30 14:41:08 +02:00
|
|
|
peer.FlushNonceQueue()
|
|
|
|
goto NextPacket
|
2017-11-30 23:22:40 +01:00
|
|
|
case <-peer.signal.stop.Wait():
|
2017-06-30 14:41:08 +02:00
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
// populate work element
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
elem.peer = peer
|
|
|
|
elem.nonce = atomic.AddUint64(&keyPair.sendNonce, 1) - 1
|
|
|
|
elem.keyPair = keyPair
|
|
|
|
elem.dropped = AtomicFalse
|
|
|
|
elem.mutex.Lock()
|
2017-07-06 15:43:55 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
// add to parallel and sequential queue
|
2017-07-06 15:43:55 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
addToEncryptionQueue(device.queue.encryption, elem)
|
|
|
|
addToOutboundQueue(peer.queue.outbound, elem)
|
2017-06-26 13:14:02 +02:00
|
|
|
}
|
2017-09-09 15:03:01 +02:00
|
|
|
}
|
2017-06-26 13:14:02 +02:00
|
|
|
}
|
|
|
|
|
2017-06-28 23:45:45 +02:00
|
|
|
/* Encrypts the elements in the queue
|
|
|
|
* and marks them for sequential consumption (by releasing the mutex)
|
2017-06-26 22:07:29 +02:00
|
|
|
*
|
2017-06-28 23:45:45 +02:00
|
|
|
* Obs. One instance per core
|
2017-06-26 22:07:29 +02:00
|
|
|
*/
|
2017-06-28 23:45:45 +02:00
|
|
|
func (device *Device) RoutineEncryption() {
|
2017-07-17 16:16:18 +02:00
|
|
|
|
2017-06-26 22:07:29 +02:00
|
|
|
var nonce [chacha20poly1305.NonceSize]byte
|
2017-07-17 16:16:18 +02:00
|
|
|
|
|
|
|
logDebug := device.log.Debug
|
|
|
|
logDebug.Println("Routine, encryption worker, started")
|
|
|
|
|
|
|
|
for {
|
|
|
|
|
|
|
|
// fetch next element
|
|
|
|
|
|
|
|
select {
|
2017-12-01 23:37:26 +01:00
|
|
|
case <-device.signal.stop.Wait():
|
2017-07-17 16:16:18 +02:00
|
|
|
logDebug.Println("Routine, encryption worker, stopped")
|
|
|
|
return
|
2017-07-08 23:51:26 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
case elem := <-device.queue.encryption:
|
2017-07-08 23:51:26 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
// check if dropped
|
|
|
|
|
|
|
|
if elem.IsDropped() {
|
|
|
|
continue
|
|
|
|
}
|
2017-06-28 23:45:45 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
// populate header fields
|
2017-07-02 15:28:38 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
header := elem.buffer[:MessageTransportHeaderSize]
|
2017-06-26 13:14:02 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
fieldType := header[0:4]
|
|
|
|
fieldReceiver := header[4:8]
|
|
|
|
fieldNonce := header[8:16]
|
2017-07-02 15:28:38 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
binary.LittleEndian.PutUint32(fieldType, MessageTransportType)
|
|
|
|
binary.LittleEndian.PutUint32(fieldReceiver, elem.keyPair.remoteIndex)
|
|
|
|
binary.LittleEndian.PutUint64(fieldNonce, elem.nonce)
|
2017-07-15 16:27:59 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
// pad content to multiple of 16
|
2017-07-15 16:27:59 +02:00
|
|
|
|
2017-09-09 15:03:01 +02:00
|
|
|
mtu := int(atomic.LoadInt32(&device.tun.mtu))
|
|
|
|
rem := len(elem.packet) % PaddingMultiple
|
|
|
|
if rem > 0 {
|
|
|
|
for i := 0; i < PaddingMultiple-rem && len(elem.packet) < mtu; i++ {
|
|
|
|
elem.packet = append(elem.packet, 0)
|
|
|
|
}
|
2017-08-04 16:15:53 +02:00
|
|
|
}
|
2017-07-02 15:28:38 +02:00
|
|
|
|
2017-09-20 09:26:08 +02:00
|
|
|
// encrypt content and release to consumer
|
2017-09-09 15:03:01 +02:00
|
|
|
|
|
|
|
binary.LittleEndian.PutUint64(nonce[4:], elem.nonce)
|
2017-09-20 09:26:08 +02:00
|
|
|
elem.packet = elem.keyPair.send.Seal(
|
|
|
|
header,
|
|
|
|
nonce[:],
|
|
|
|
elem.packet,
|
|
|
|
nil,
|
|
|
|
)
|
2017-09-09 15:03:01 +02:00
|
|
|
elem.mutex.Unlock()
|
|
|
|
}
|
2017-06-28 23:45:45 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Sequentially reads packets from queue and sends to endpoint
|
|
|
|
*
|
|
|
|
* Obs. Single instance per peer.
|
|
|
|
* The routine terminates then the outbound queue is closed.
|
|
|
|
*/
|
2017-06-30 14:41:08 +02:00
|
|
|
func (peer *Peer) RoutineSequentialSender() {
|
|
|
|
device := peer.device
|
|
|
|
|
2017-07-08 23:51:26 +02:00
|
|
|
logDebug := device.log.Debug
|
2017-07-13 14:32:40 +02:00
|
|
|
logDebug.Println("Routine, sequential sender, started for", peer.String())
|
2017-07-08 23:51:26 +02:00
|
|
|
|
2017-06-30 14:41:08 +02:00
|
|
|
for {
|
|
|
|
select {
|
2017-11-30 23:22:40 +01:00
|
|
|
|
|
|
|
case <-peer.signal.stop.Wait():
|
|
|
|
logDebug.Println(
|
|
|
|
"Routine, sequential sender, stopped for", peer.String())
|
2017-06-30 14:41:08 +02:00
|
|
|
return
|
2017-07-13 14:32:40 +02:00
|
|
|
|
2017-07-17 16:16:18 +02:00
|
|
|
case elem := <-peer.queue.outbound:
|
|
|
|
elem.mutex.Lock()
|
2017-07-27 23:45:37 +02:00
|
|
|
if elem.IsDropped() {
|
|
|
|
continue
|
|
|
|
}
|
2017-07-08 23:51:26 +02:00
|
|
|
|
2017-07-27 23:45:37 +02:00
|
|
|
// send message and return buffer to pool
|
2017-07-14 14:25:18 +02:00
|
|
|
|
2017-07-27 23:45:37 +02:00
|
|
|
length := uint64(len(elem.packet))
|
2017-10-16 21:33:47 +02:00
|
|
|
err := peer.SendBuffer(elem.packet)
|
2017-07-27 23:45:37 +02:00
|
|
|
device.PutMessageBuffer(elem.buffer)
|
|
|
|
if err != nil {
|
2017-09-09 15:03:01 +02:00
|
|
|
logDebug.Println("Failed to send authenticated packet to peer", peer.String())
|
2017-07-27 23:45:37 +02:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
atomic.AddUint64(&peer.stats.txBytes, length)
|
2017-07-18 15:22:56 +02:00
|
|
|
|
2017-07-27 23:45:37 +02:00
|
|
|
// update timers
|
2017-07-17 16:16:18 +02:00
|
|
|
|
2017-08-04 16:15:53 +02:00
|
|
|
peer.TimerAnyAuthenticatedPacketTraversal()
|
2017-07-27 23:45:37 +02:00
|
|
|
if len(elem.packet) != MessageKeepaliveSize {
|
|
|
|
peer.TimerDataSent()
|
|
|
|
}
|
|
|
|
peer.KeepKeyFreshSending()
|
2017-06-30 14:41:08 +02:00
|
|
|
}
|
2017-06-26 13:14:02 +02:00
|
|
|
}
|
|
|
|
}
|