mirror of
https://github.com/slackhq/nebula.git
synced 2026-08-15 15:16:59 +02:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 16a836a73f |
@@ -1,113 +0,0 @@
|
|||||||
name: Code-sign Windows binaries
|
|
||||||
description: >
|
|
||||||
Sign every .exe under a given path in place via the DefinedNet code-signer
|
|
||||||
Lambda. If `role` or `bucket` is empty, logs a notice and skips signing so
|
|
||||||
forks and dev branches without AWS access still produce usable builds.
|
|
||||||
|
|
||||||
inputs:
|
|
||||||
path:
|
|
||||||
description: "Directory whose .exe files should be signed in place"
|
|
||||||
required: true
|
|
||||||
role:
|
|
||||||
description: "IAM role ARN to assume via OIDC; empty disables signing"
|
|
||||||
required: false
|
|
||||||
default: ""
|
|
||||||
bucket:
|
|
||||||
description: "S3 staging bucket the code-signer Lambda reads from; empty disables signing"
|
|
||||||
required: false
|
|
||||||
default: ""
|
|
||||||
region:
|
|
||||||
description: "AWS region for the role and Lambda"
|
|
||||||
required: false
|
|
||||||
default: "us-east-2"
|
|
||||||
function-name:
|
|
||||||
description: "Code-signer Lambda function name"
|
|
||||||
required: false
|
|
||||||
default: "code-signer"
|
|
||||||
key-prefix:
|
|
||||||
description: "S3 key prefix the caller is authorized to write under"
|
|
||||||
required: false
|
|
||||||
default: "code-signing/slackhq/nebula"
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: composite
|
|
||||||
steps:
|
|
||||||
- name: Skip notice
|
|
||||||
if: inputs.role == '' || inputs.bucket == ''
|
|
||||||
shell: sh
|
|
||||||
run: echo "::notice::code-signer role or bucket not set; skipping code signing."
|
|
||||||
|
|
||||||
- name: Configure AWS credentials
|
|
||||||
if: inputs.role != '' && inputs.bucket != ''
|
|
||||||
uses: aws-actions/configure-aws-credentials@v6
|
|
||||||
with:
|
|
||||||
role-to-assume: ${{ inputs.role }}
|
|
||||||
aws-region: ${{ inputs.region }}
|
|
||||||
# Default is 12 retries to ride out IAM trust-policy propagation; once
|
|
||||||
# the role is stable we want a real misconfiguration to fail fast.
|
|
||||||
retry-max-attempts: 5
|
|
||||||
|
|
||||||
- name: Sign .exe files
|
|
||||||
if: inputs.role != '' && inputs.bucket != ''
|
|
||||||
shell: sh
|
|
||||||
env:
|
|
||||||
SIGN_PATH: ${{ inputs.path }}
|
|
||||||
BUCKET: ${{ inputs.bucket }}
|
|
||||||
FUNCTION_NAME: ${{ inputs.function-name }}
|
|
||||||
KEY_PREFIX: ${{ inputs.key-prefix }}
|
|
||||||
run: |
|
|
||||||
set -eu
|
|
||||||
RUN="${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"
|
|
||||||
|
|
||||||
find "$SIGN_PATH" -name '*.exe' -print | while read -r path
|
|
||||||
do
|
|
||||||
rel=${path#"$SIGN_PATH"/}
|
|
||||||
file=$(basename "$path")
|
|
||||||
name=${file%.exe}
|
|
||||||
prefix="${KEY_PREFIX}/${RUN}"
|
|
||||||
src="${prefix}/unsigned/${rel}"
|
|
||||||
dst="${prefix}/signed/${rel}"
|
|
||||||
|
|
||||||
echo "::group::Sign ${rel}"
|
|
||||||
echo "Uploading unsigned to s3://${BUCKET}/${src}"
|
|
||||||
aws s3 cp --no-progress "$path" "s3://${BUCKET}/${src}" >/dev/null
|
|
||||||
|
|
||||||
echo "Invoking ${FUNCTION_NAME} Lambda"
|
|
||||||
payload=$(jq -nc \
|
|
||||||
--arg s "$src" \
|
|
||||||
--arg d "$dst" \
|
|
||||||
--arg p "$name" \
|
|
||||||
'{source_key: $s, dest_key: $d, program_name: $p}')
|
|
||||||
meta=$(aws lambda invoke \
|
|
||||||
--function-name "$FUNCTION_NAME" \
|
|
||||||
--cli-binary-format raw-in-base64-out \
|
|
||||||
--payload "$payload" \
|
|
||||||
--output json \
|
|
||||||
/tmp/sign-resp.json)
|
|
||||||
if echo "$meta" | jq -e '.FunctionError != null' >/dev/null
|
|
||||||
then
|
|
||||||
echo "::endgroup::"
|
|
||||||
echo "::error::code-signer Lambda failed for ${rel}"
|
|
||||||
cat /tmp/sign-resp.json >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Downloading signed back to ${path}"
|
|
||||||
aws s3 cp --no-progress "s3://${BUCKET}/${dst}" "$path" >/dev/null
|
|
||||||
|
|
||||||
aws s3 rm "s3://${BUCKET}/${src}" >/dev/null 2>&1 || true
|
|
||||||
aws s3 rm "s3://${BUCKET}/${dst}" >/dev/null 2>&1 || true
|
|
||||||
|
|
||||||
# Sanity-check the bytes we got back actually carry an Authenticode
|
|
||||||
# signature that this machine can validate end to end.
|
|
||||||
status=$(powershell -NoProfile -Command "(Get-AuthenticodeSignature -FilePath '$path').Status" | tr -d '\r')
|
|
||||||
if [ "$status" != "Valid" ]
|
|
||||||
then
|
|
||||||
echo "::endgroup::"
|
|
||||||
echo "::error::${rel} signature status: ${status} (expected Valid)"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Signed ${rel} (sha256=$(jq -r '.sha256' /tmp/sign-resp.json), status=${status})"
|
|
||||||
echo "::endgroup::"
|
|
||||||
done
|
|
||||||
@@ -24,7 +24,7 @@ jobs:
|
|||||||
mv build/*.tar.gz release
|
mv build/*.tar.gz release
|
||||||
|
|
||||||
- name: Upload artifacts
|
- name: Upload artifacts
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v6
|
||||||
with:
|
with:
|
||||||
name: linux-latest
|
name: linux-latest
|
||||||
path: release
|
path: release
|
||||||
@@ -32,9 +32,6 @@ jobs:
|
|||||||
build-windows:
|
build-windows:
|
||||||
name: Build Windows
|
name: Build Windows
|
||||||
runs-on: windows-latest
|
runs-on: windows-latest
|
||||||
permissions:
|
|
||||||
id-token: write
|
|
||||||
contents: read
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v6
|
- uses: actions/checkout@v6
|
||||||
|
|
||||||
@@ -57,15 +54,8 @@ jobs:
|
|||||||
mkdir build\dist\windows
|
mkdir build\dist\windows
|
||||||
mv dist\windows\wintun build\dist\windows\
|
mv dist\windows\wintun build\dist\windows\
|
||||||
|
|
||||||
- name: Code-sign
|
|
||||||
uses: ./.github/actions/code-sign
|
|
||||||
with:
|
|
||||||
path: build
|
|
||||||
role: ${{ secrets.DEFINED_CODE_SIGNER_ROLE }}
|
|
||||||
bucket: ${{ secrets.DEFINED_CODE_SIGNER_BUCKET }}
|
|
||||||
|
|
||||||
- name: Upload artifacts
|
- name: Upload artifacts
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v6
|
||||||
with:
|
with:
|
||||||
name: windows-latest
|
name: windows-latest
|
||||||
path: build
|
path: build
|
||||||
@@ -85,7 +75,7 @@ jobs:
|
|||||||
|
|
||||||
- name: Import certificates
|
- name: Import certificates
|
||||||
if: env.HAS_SIGNING_CREDS == 'true'
|
if: env.HAS_SIGNING_CREDS == 'true'
|
||||||
uses: Apple-Actions/import-codesign-certs@v7
|
uses: Apple-Actions/import-codesign-certs@v6
|
||||||
with:
|
with:
|
||||||
p12-file-base64: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_P12_BASE64 }}
|
p12-file-base64: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_P12_BASE64 }}
|
||||||
p12-password: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_PASSWORD }}
|
p12-password: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_PASSWORD }}
|
||||||
@@ -114,7 +104,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
- name: Upload artifacts
|
- name: Upload artifacts
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v6
|
||||||
with:
|
with:
|
||||||
name: darwin-latest
|
name: darwin-latest
|
||||||
path: ./release/*
|
path: ./release/*
|
||||||
@@ -138,21 +128,21 @@ jobs:
|
|||||||
|
|
||||||
- name: Download artifacts
|
- name: Download artifacts
|
||||||
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
||||||
uses: actions/download-artifact@v8
|
uses: actions/download-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: linux-latest
|
name: linux-latest
|
||||||
path: artifacts
|
path: artifacts
|
||||||
|
|
||||||
- name: Login to Docker Hub
|
- name: Login to Docker Hub
|
||||||
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
username: ${{ vars.DOCKERHUB_USERNAME }}
|
username: ${{ vars.DOCKERHUB_USERNAME }}
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
||||||
uses: docker/setup-buildx-action@v4
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Build and push images
|
- name: Build and push images
|
||||||
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
|
||||||
@@ -173,7 +163,7 @@ jobs:
|
|||||||
- uses: actions/checkout@v6
|
- uses: actions/checkout@v6
|
||||||
|
|
||||||
- name: Download artifacts
|
- name: Download artifacts
|
||||||
uses: actions/download-artifact@v8
|
uses: actions/download-artifact@v7
|
||||||
with:
|
with:
|
||||||
path: artifacts
|
path: artifacts
|
||||||
|
|
||||||
|
|||||||
@@ -14,18 +14,10 @@ on:
|
|||||||
- 'go.sum'
|
- 'go.sum'
|
||||||
jobs:
|
jobs:
|
||||||
|
|
||||||
smoke-extra-libvirt:
|
smoke-extra:
|
||||||
if: github.ref == 'refs/heads/master' || contains(github.event.pull_request.labels.*.name, 'smoke-test-extra')
|
if: github.ref == 'refs/heads/master' || contains(github.event.pull_request.labels.*.name, 'smoke-test-extra')
|
||||||
name: ${{ matrix.target }}
|
name: Run extra smoke tests
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
target:
|
|
||||||
- freebsd-amd64
|
|
||||||
- openbsd-amd64
|
|
||||||
- netbsd-amd64
|
|
||||||
- linux-amd64-ipv6disable
|
|
||||||
env:
|
env:
|
||||||
VAGRANT_DEFAULT_PROVIDER: libvirt
|
VAGRANT_DEFAULT_PROVIDER: libvirt
|
||||||
steps:
|
steps:
|
||||||
@@ -48,85 +40,28 @@ jobs:
|
|||||||
sudo chmod 666 /var/run/libvirt/libvirt-sock
|
sudo chmod 666 /var/run/libvirt/libvirt-sock
|
||||||
vagrant plugin install vagrant-libvirt
|
vagrant plugin install vagrant-libvirt
|
||||||
|
|
||||||
- name: ${{ matrix.target }}
|
- name: freebsd-amd64
|
||||||
run: make smoke-vagrant/${{ matrix.target }}
|
run: make smoke-vagrant/freebsd-amd64
|
||||||
|
|
||||||
timeout-minutes: 30
|
- name: openbsd-amd64
|
||||||
|
run: make smoke-vagrant/openbsd-amd64
|
||||||
|
|
||||||
# linux-386 needs VirtualBox, which conflicts with KVM/libvirt -- isolated job.
|
- name: netbsd-amd64
|
||||||
smoke-extra-virtualbox:
|
run: make smoke-vagrant/netbsd-amd64
|
||||||
if: github.ref == 'refs/heads/master' || contains(github.event.pull_request.labels.*.name, 'smoke-test-extra')
|
|
||||||
name: linux-386
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
env:
|
|
||||||
VAGRANT_DEFAULT_PROVIDER: virtualbox
|
|
||||||
steps:
|
|
||||||
|
|
||||||
- uses: actions/checkout@v6
|
- name: linux-amd64-ipv6disable
|
||||||
|
run: make smoke-vagrant/linux-amd64-ipv6disable
|
||||||
|
|
||||||
- uses: actions/setup-go@v6
|
# linux-386 runs last because it requires disabling KVM to use VirtualBox,
|
||||||
with:
|
# which prevents libvirt (used by the other tests) from working after this point.
|
||||||
go-version: '1.25'
|
- name: install virtualbox for i386 test
|
||||||
check-latest: true
|
|
||||||
|
|
||||||
- name: add hashicorp source
|
|
||||||
run: wget -O- https://apt.releases.hashicorp.com/gpg | gpg --dearmor | sudo tee /usr/share/keyrings/hashicorp-archive-keyring.gpg && echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
|
|
||||||
|
|
||||||
- name: install vagrant and virtualbox
|
|
||||||
run: |
|
run: |
|
||||||
sudo apt-get update && sudo apt-get install -y vagrant virtualbox
|
sudo apt-get install -y virtualbox
|
||||||
sudo rmmod kvm_amd kvm_intel kvm 2>/dev/null || true
|
sudo rmmod kvm_amd kvm_intel kvm 2>/dev/null || true
|
||||||
|
|
||||||
- name: linux-386
|
- name: linux-386
|
||||||
|
env:
|
||||||
|
VAGRANT_DEFAULT_PROVIDER: virtualbox
|
||||||
run: make smoke-vagrant/linux-386
|
run: make smoke-vagrant/linux-386
|
||||||
|
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
|
|
||||||
smoke-windows:
|
|
||||||
if: github.ref == 'refs/heads/master' || contains(github.event.pull_request.labels.*.name, 'smoke-test-extra')
|
|
||||||
name: Run windows smoke test
|
|
||||||
runs-on: windows-latest
|
|
||||||
steps:
|
|
||||||
|
|
||||||
- uses: actions/checkout@v6
|
|
||||||
|
|
||||||
- uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: '1.25'
|
|
||||||
check-latest: true
|
|
||||||
|
|
||||||
# WSL2 + Ubuntu so the smoke can run a real linux peer with its own
|
|
||||||
# netns. iputils-ping is needed for the in-WSL ping check. WSL1 has no
|
|
||||||
# real kernel and would lack /dev/net/tun, so we have to force WSL2.
|
|
||||||
- uses: Vampire/setup-wsl@v3
|
|
||||||
with:
|
|
||||||
distribution: Ubuntu-24.04
|
|
||||||
additional-packages: iputils-ping iproute2
|
|
||||||
|
|
||||||
# Vampire/setup-wsl provisions WSL1 even when the WSL2 platform is present.
|
|
||||||
# Convert the distro to WSL2 explicitly before we try to use /dev/net/tun.
|
|
||||||
- name: convert distro to WSL2
|
|
||||||
shell: pwsh
|
|
||||||
run: |
|
|
||||||
wsl --set-version Ubuntu-24.04 2
|
|
||||||
wsl --shutdown
|
|
||||||
wsl --list --verbose
|
|
||||||
|
|
||||||
- name: build windows nebula
|
|
||||||
run: make bin-windows
|
|
||||||
|
|
||||||
- name: build linux nebula for WSL
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
GOOS: linux
|
|
||||||
GOARCH: amd64
|
|
||||||
run: |
|
|
||||||
mkdir -p build/linux-amd64
|
|
||||||
go build -o build/linux-amd64/nebula ./cmd/nebula
|
|
||||||
|
|
||||||
- name: run smoke-windows
|
|
||||||
shell: pwsh
|
|
||||||
working-directory: ./.github/workflows/smoke
|
|
||||||
run: ./smoke-windows.ps1
|
|
||||||
|
|
||||||
timeout-minutes: 15
|
|
||||||
|
|||||||
@@ -1,272 +0,0 @@
|
|||||||
#!/usr/bin/env pwsh
|
|
||||||
# Windows smoke test for the nebula tun + UDP + NLM code paths.
|
|
||||||
#
|
|
||||||
# Topology:
|
|
||||||
# - lighthouse runs natively on the Windows host (wintun + windows UDP)
|
|
||||||
# - peer runs inside WSL2 (Linux build of nebula, /dev/net/tun)
|
|
||||||
#
|
|
||||||
# WSL2 gives us a real netns boundary so the loopback fast-path on Windows
|
|
||||||
# does not short-circuit the overlay -- when WSL pings the lighthouse VPN IP,
|
|
||||||
# Linux has no idea that IP is local to the Windows host, so the packet is
|
|
||||||
# forced through nebula. Same in reverse.
|
|
||||||
|
|
||||||
$ErrorActionPreference = 'Stop'
|
|
||||||
|
|
||||||
# wsl.exe emits UTF-16 LE by default which PowerShell reads as bytes, mangling
|
|
||||||
# every captured string. WSL_UTF8 makes wsl.exe emit UTF-8 instead.
|
|
||||||
$env:WSL_UTF8 = '1'
|
|
||||||
|
|
||||||
$RepoRoot = Resolve-Path "$PSScriptRoot\..\..\.."
|
|
||||||
$Nebula = Join-Path $RepoRoot 'nebula.exe'
|
|
||||||
$NebulaCert = Join-Path $RepoRoot 'nebula-cert.exe'
|
|
||||||
$NebulaLinux = Join-Path $RepoRoot 'build\linux-amd64\nebula'
|
|
||||||
|
|
||||||
if (-not (Test-Path $Nebula)) { throw "missing $Nebula; run 'make bin-windows' first" }
|
|
||||||
if (-not (Test-Path $NebulaCert)) { throw "missing $NebulaCert; run 'make bin-windows' first" }
|
|
||||||
if (-not (Test-Path $NebulaLinux)) { throw "missing $NebulaLinux; build the linux nebula first" }
|
|
||||||
|
|
||||||
# Matches the distro installed by Vampire/setup-wsl in smoke-extra.yml.
|
|
||||||
$Distro = 'Ubuntu-24.04'
|
|
||||||
$listed = (wsl --list --quiet 2>$null) -join "`n"
|
|
||||||
if ($listed -notmatch [regex]::Escape($Distro)) {
|
|
||||||
throw "WSL distro $Distro not registered. Got: $listed"
|
|
||||||
}
|
|
||||||
Write-Host "Using WSL distro: $Distro"
|
|
||||||
|
|
||||||
# Windows host as seen from inside WSL: WSL's default-route gateway. We extract
|
|
||||||
# it with a regex rather than awk fields so PowerShell does not eat any '$N'
|
|
||||||
# tokens, and tabs/double-spaces in `ip route` output do not confuse a cut.
|
|
||||||
$ipCmd = 'ip route show default | grep -oE "([0-9]+\.){3}[0-9]+" | head -1'
|
|
||||||
$WindowsIp = (wsl -d $Distro -- bash -c $ipCmd).Trim()
|
|
||||||
if (-not $WindowsIp) { throw "could not determine Windows host IP from WSL" }
|
|
||||||
Write-Host "Windows host IP from WSL: $WindowsIp"
|
|
||||||
|
|
||||||
$WorkDir = Join-Path $env:TEMP 'nebula-smoke-windows'
|
|
||||||
if (Test-Path $WorkDir) { Remove-Item -Recurse -Force $WorkDir }
|
|
||||||
New-Item -ItemType Directory -Path $WorkDir | Out-Null
|
|
||||||
|
|
||||||
$WslDir = '/tmp/nebula-smoke'
|
|
||||||
wsl -d $Distro -- bash -c "rm -rf $WslDir && mkdir -p $WslDir" | Out-Null
|
|
||||||
|
|
||||||
$DevName = 'nebula-smoke'
|
|
||||||
$Ip1 = '192.168.241.1'
|
|
||||||
$Ip2 = '192.168.241.2'
|
|
||||||
$Port = 4242
|
|
||||||
|
|
||||||
& $NebulaCert ca -name 'smoke-ca' -out-crt "$WorkDir\ca.crt" -out-key "$WorkDir\ca.key"
|
|
||||||
if ($LASTEXITCODE -ne 0) { throw "nebula-cert ca failed (exit $LASTEXITCODE)" }
|
|
||||||
|
|
||||||
& $NebulaCert sign -name 'lighthouse' -networks "$Ip1/24" -ca-crt "$WorkDir\ca.crt" -ca-key "$WorkDir\ca.key" -out-crt "$WorkDir\lighthouse.crt" -out-key "$WorkDir\lighthouse.key"
|
|
||||||
if ($LASTEXITCODE -ne 0) { throw "nebula-cert sign lighthouse failed (exit $LASTEXITCODE)" }
|
|
||||||
|
|
||||||
& $NebulaCert sign -name 'peer' -networks "$Ip2/24" -ca-crt "$WorkDir\ca.crt" -ca-key "$WorkDir\ca.key" -out-crt "$WorkDir\peer.crt" -out-key "$WorkDir\peer.key"
|
|
||||||
if ($LASTEXITCODE -ne 0) { throw "nebula-cert sign peer failed (exit $LASTEXITCODE)" }
|
|
||||||
|
|
||||||
# Windows lighthouse config.
|
|
||||||
@"
|
|
||||||
pki:
|
|
||||||
ca: $WorkDir\ca.crt
|
|
||||||
cert: $WorkDir\lighthouse.crt
|
|
||||||
key: $WorkDir\lighthouse.key
|
|
||||||
static_host_map: {}
|
|
||||||
lighthouse:
|
|
||||||
am_lighthouse: true
|
|
||||||
interval: 60
|
|
||||||
hosts: []
|
|
||||||
listen:
|
|
||||||
host: 0.0.0.0
|
|
||||||
port: $Port
|
|
||||||
tun:
|
|
||||||
disabled: false
|
|
||||||
dev: $DevName
|
|
||||||
drop_local_broadcast: false
|
|
||||||
drop_multicast: false
|
|
||||||
tx_queue: 500
|
|
||||||
mtu: 1300
|
|
||||||
network_category: private
|
|
||||||
logging:
|
|
||||||
level: info
|
|
||||||
format: text
|
|
||||||
firewall:
|
|
||||||
outbound_action: drop
|
|
||||||
inbound_action: drop
|
|
||||||
conntrack:
|
|
||||||
tcp_timeout: 12m
|
|
||||||
udp_timeout: 3m
|
|
||||||
default_timeout: 10m
|
|
||||||
outbound:
|
|
||||||
- port: any
|
|
||||||
proto: any
|
|
||||||
host: any
|
|
||||||
inbound:
|
|
||||||
- port: any
|
|
||||||
proto: any
|
|
||||||
host: any
|
|
||||||
"@ | Out-File -FilePath "$WorkDir\lighthouse.yml" -Encoding utf8
|
|
||||||
|
|
||||||
# WSL peer config (paths are POSIX, deliberately).
|
|
||||||
@"
|
|
||||||
pki:
|
|
||||||
ca: $WslDir/ca.crt
|
|
||||||
cert: $WslDir/peer.crt
|
|
||||||
key: $WslDir/peer.key
|
|
||||||
static_host_map:
|
|
||||||
"${Ip1}": ["${WindowsIp}:$Port"]
|
|
||||||
lighthouse:
|
|
||||||
am_lighthouse: false
|
|
||||||
interval: 60
|
|
||||||
hosts:
|
|
||||||
- "${Ip1}"
|
|
||||||
listen:
|
|
||||||
host: 0.0.0.0
|
|
||||||
port: 0
|
|
||||||
tun:
|
|
||||||
disabled: false
|
|
||||||
dev: nebula1
|
|
||||||
drop_local_broadcast: false
|
|
||||||
drop_multicast: false
|
|
||||||
tx_queue: 500
|
|
||||||
mtu: 1300
|
|
||||||
logging:
|
|
||||||
level: info
|
|
||||||
format: text
|
|
||||||
firewall:
|
|
||||||
outbound_action: drop
|
|
||||||
inbound_action: drop
|
|
||||||
conntrack:
|
|
||||||
tcp_timeout: 12m
|
|
||||||
udp_timeout: 3m
|
|
||||||
default_timeout: 10m
|
|
||||||
outbound:
|
|
||||||
- port: any
|
|
||||||
proto: any
|
|
||||||
host: any
|
|
||||||
inbound:
|
|
||||||
- port: any
|
|
||||||
proto: any
|
|
||||||
host: any
|
|
||||||
"@ | Out-File -FilePath "$WorkDir\peer.yml" -Encoding utf8
|
|
||||||
|
|
||||||
# Stage WSL artifacts. Convert Windows paths to WSL paths ourselves rather than
|
|
||||||
# calling `wslpath`, because PowerShell's argument-passing to external EXEs
|
|
||||||
# strips backslashes from path arguments in ways that are hard to escape around.
|
|
||||||
function ConvertTo-WslPath {
|
|
||||||
param([string]$WindowsPath)
|
|
||||||
if ($WindowsPath -notmatch '^([A-Za-z]):\\(.*)$') {
|
|
||||||
throw "cannot convert path to WSL: $WindowsPath"
|
|
||||||
}
|
|
||||||
return "/mnt/$($matches[1].ToLower())/$($matches[2].Replace('\','/'))"
|
|
||||||
}
|
|
||||||
|
|
||||||
$WslWorkDir = ConvertTo-WslPath $WorkDir
|
|
||||||
$WslNebulaPath = ConvertTo-WslPath $NebulaLinux
|
|
||||||
wsl -d $Distro -- bash -c "cp '$WslWorkDir/ca.crt' '$WslWorkDir/peer.crt' '$WslWorkDir/peer.key' '$WslWorkDir/peer.yml' $WslDir/ && cp '$WslNebulaPath' $WslDir/nebula && chmod +x $WslDir/nebula"
|
|
||||||
|
|
||||||
# Make sure WSL has tun support and /dev/net/tun is usable before starting
|
|
||||||
# nebula. Diagnostics first so a fail here points at the real problem (e.g.
|
|
||||||
# WSL1 distros do not have a real kernel and will not have tun).
|
|
||||||
Write-Host '=== WSL diagnostic ==='
|
|
||||||
wsl --version 2>&1 | Out-Host
|
|
||||||
wsl --list --verbose 2>&1 | Out-Host
|
|
||||||
wsl -d $Distro -u root -- uname -a | Out-Host
|
|
||||||
wsl -d $Distro -u root -- bash -c "modprobe tun 2>&1 || true; mkdir -p /dev/net; [ -c /dev/net/tun ] || mknod /dev/net/tun c 10 200; chmod 600 /dev/net/tun; ls -l /dev/net/tun"
|
|
||||||
if ($LASTEXITCODE -ne 0) { throw "failed to prepare /dev/net/tun in WSL (TUN support missing?)" }
|
|
||||||
|
|
||||||
# Deliberately no New-NetFirewallRule calls here -- nebula's windows_bypass_wdf
|
|
||||||
# feature is supposed to install WFP permit filters that let inbound traffic
|
|
||||||
# through Windows Defender Firewall on its own. If this smoke regresses, that
|
|
||||||
# feature regressed.
|
|
||||||
|
|
||||||
$lhOut = Join-Path $WorkDir 'lighthouse.out.log'
|
|
||||||
$lhErr = Join-Path $WorkDir 'lighthouse.err.log'
|
|
||||||
$lhProc = Start-Process -FilePath $Nebula -ArgumentList @('-config', "$WorkDir\lighthouse.yml") `
|
|
||||||
-PassThru -NoNewWindow `
|
|
||||||
-RedirectStandardOutput $lhOut `
|
|
||||||
-RedirectStandardError $lhErr
|
|
||||||
|
|
||||||
# Run nebula in WSL as root with no sudo + no shell wrapper. PowerShell's
|
|
||||||
# Start-Process arg quoting mangles `bash -c "..."` strings that contain
|
|
||||||
# spaces/redirections, so we skip bash entirely and let Start-Process do the
|
|
||||||
# stdout/stderr capture itself.
|
|
||||||
$peerOut = Join-Path $WorkDir 'peer.out.log'
|
|
||||||
$peerErr = Join-Path $WorkDir 'peer.err.log'
|
|
||||||
$peerProc = Start-Process -FilePath 'wsl' `
|
|
||||||
-ArgumentList @('-d', $Distro, '-u', 'root', '--', "$WslDir/nebula", '-config', "$WslDir/peer.yml") `
|
|
||||||
-PassThru -NoNewWindow `
|
|
||||||
-RedirectStandardOutput $peerOut `
|
|
||||||
-RedirectStandardError $peerErr
|
|
||||||
|
|
||||||
function Wait-Until {
|
|
||||||
param([scriptblock]$Predicate, [int]$TimeoutSec, [string]$What)
|
|
||||||
$deadline = (Get-Date).AddSeconds($TimeoutSec)
|
|
||||||
while ((Get-Date) -lt $deadline) {
|
|
||||||
if (& $Predicate) { return }
|
|
||||||
Start-Sleep -Milliseconds 500
|
|
||||||
}
|
|
||||||
throw "timed out waiting for: $What"
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
|
||||||
Wait-Until -TimeoutSec 30 -What "windows wintun adapter $DevName with NetworkCategory=Private" -Predicate {
|
|
||||||
if ($lhProc.HasExited) { throw "lighthouse exited (code $($lhProc.ExitCode)) before tun was ready" }
|
|
||||||
$p = Get-NetConnectionProfile -InterfaceAlias $DevName -ErrorAction SilentlyContinue
|
|
||||||
$p -and ("$($p.NetworkCategory)" -ieq 'Private')
|
|
||||||
}
|
|
||||||
Write-Host "OK: $DevName NetworkCategory=Private"
|
|
||||||
|
|
||||||
Wait-Until -TimeoutSec 30 -What "WSL nebula1 with $Ip2" -Predicate {
|
|
||||||
if ($peerProc.HasExited) { throw "peer exited (code $($peerProc.ExitCode)) before tun was ready" }
|
|
||||||
$r = wsl -d $Distro -u root -- bash -c "ip -o addr show nebula1 2>/dev/null | grep -q 'inet $Ip2' && echo yes"
|
|
||||||
("$r").Trim() -eq 'yes'
|
|
||||||
}
|
|
||||||
Write-Host "OK: WSL nebula1 has $Ip2"
|
|
||||||
|
|
||||||
Wait-Until -TimeoutSec 30 -What "ping from WSL peer to windows lighthouse ($Ip1)" -Predicate {
|
|
||||||
if ($peerProc.HasExited) { throw "peer exited (code $($peerProc.ExitCode)) before ping succeeded" }
|
|
||||||
$r = wsl -d $Distro -u root -- bash -c "ping -c1 -W1 $Ip1 >/dev/null 2>&1 && echo OK"
|
|
||||||
("$r").Trim() -eq 'OK'
|
|
||||||
}
|
|
||||||
Write-Host "OK: WSL peer -> windows lighthouse"
|
|
||||||
|
|
||||||
Wait-Until -TimeoutSec 30 -What "ping from windows lighthouse to WSL peer ($Ip2)" -Predicate {
|
|
||||||
$null = & ping.exe -n 1 -w 1000 $Ip2
|
|
||||||
$LASTEXITCODE -eq 0
|
|
||||||
}
|
|
||||||
Write-Host "OK: windows lighthouse -> WSL peer"
|
|
||||||
|
|
||||||
Write-Host ''
|
|
||||||
Write-Host 'All smoke checks passed.'
|
|
||||||
}
|
|
||||||
catch {
|
|
||||||
Write-Host ''
|
|
||||||
Write-Host '=== lighthouse stdout ==='
|
|
||||||
Get-Content $lhOut -ErrorAction SilentlyContinue | Out-Host
|
|
||||||
Write-Host '=== lighthouse stderr ==='
|
|
||||||
Get-Content $lhErr -ErrorAction SilentlyContinue | Out-Host
|
|
||||||
Write-Host '=== peer stdout ==='
|
|
||||||
Get-Content $peerOut -ErrorAction SilentlyContinue | Out-Host
|
|
||||||
Write-Host '=== peer stderr ==='
|
|
||||||
Get-Content $peerErr -ErrorAction SilentlyContinue | Out-Host
|
|
||||||
Write-Host '=== nebula WFP filters ==='
|
|
||||||
# Dump nebula-installed filters so we can verify they got registered with
|
|
||||||
# the conditions we expect.
|
|
||||||
$wfpDump = Join-Path $WorkDir 'wfp.xml'
|
|
||||||
netsh wfp show filters file=$wfpDump 2>&1 | Out-Null
|
|
||||||
if (Test-Path $wfpDump) {
|
|
||||||
Select-String -Path $wfpDump -Pattern 'Nebula' -Context 0,80 -ErrorAction SilentlyContinue | Out-Host
|
|
||||||
}
|
|
||||||
throw
|
|
||||||
}
|
|
||||||
finally {
|
|
||||||
if (-not $lhProc.HasExited) {
|
|
||||||
Stop-Process -Id $lhProc.Id -Force -ErrorAction SilentlyContinue
|
|
||||||
$lhProc.WaitForExit(5000) | Out-Null
|
|
||||||
}
|
|
||||||
wsl -d $Distro -u root -- bash -c "pkill -f $WslDir/nebula 2>/dev/null; true" | Out-Null
|
|
||||||
# pkill returns 1 when no match and wsl propagates that; the smoke is done
|
|
||||||
# so we don't want it to leak into the script's exit code.
|
|
||||||
$global:LASTEXITCODE = 0
|
|
||||||
if ($peerProc -and -not $peerProc.HasExited) {
|
|
||||||
Stop-Process -Id $peerProc.Id -Force -ErrorAction SilentlyContinue
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
# -*- mode: ruby -*-
|
# -*- mode: ruby -*-
|
||||||
# vi: set ft=ruby :
|
# vi: set ft=ruby :
|
||||||
Vagrant.configure("2") do |config|
|
Vagrant.configure("2") do |config|
|
||||||
config.vm.box = "DefinedNet/netbsd10"
|
config.vm.box = "generic/netbsd9"
|
||||||
|
|
||||||
config.vm.synced_folder "../build", "/nebula", type: "rsync"
|
config.vm.synced_folder "../build", "/nebula", type: "rsync"
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -45,7 +45,7 @@ jobs:
|
|||||||
- name: Build test mobile
|
- name: Build test mobile
|
||||||
run: make build-test-mobile
|
run: make build-test-mobile
|
||||||
|
|
||||||
- uses: actions/upload-artifact@v7
|
- uses: actions/upload-artifact@v6
|
||||||
with:
|
with:
|
||||||
name: e2e packet flow linux-latest
|
name: e2e packet flow linux-latest
|
||||||
path: e2e/mermaid/linux-latest
|
path: e2e/mermaid/linux-latest
|
||||||
@@ -125,7 +125,7 @@ jobs:
|
|||||||
- name: End 2 end
|
- name: End 2 end
|
||||||
run: make e2evv
|
run: make e2evv
|
||||||
|
|
||||||
- uses: actions/upload-artifact@v7
|
- uses: actions/upload-artifact@v6
|
||||||
with:
|
with:
|
||||||
name: e2e packet flow ${{ matrix.os }}
|
name: e2e packet flow ${{ matrix.os }}
|
||||||
path: e2e/mermaid/${{ matrix.os }}
|
path: e2e/mermaid/${{ matrix.os }}
|
||||||
|
|||||||
@@ -2,42 +2,24 @@ package nebula
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"math"
|
|
||||||
mathbits "math/bits"
|
|
||||||
|
|
||||||
"github.com/rcrowley/go-metrics"
|
"github.com/rcrowley/go-metrics"
|
||||||
)
|
)
|
||||||
|
|
||||||
const bitsPerWord = 64
|
|
||||||
|
|
||||||
// Bits is a sliding-window anti-replay tracker. The window is stored as a
|
|
||||||
// circular bitmap packed into uint64 words (8x denser than a []bool), so a
|
|
||||||
// length-N window costs N/8 bytes. length must be a power of two.
|
|
||||||
type Bits struct {
|
type Bits struct {
|
||||||
length uint64
|
length uint64
|
||||||
lengthMask uint64
|
|
||||||
current uint64
|
current uint64
|
||||||
bits []uint64
|
bits []bool
|
||||||
lostCounter metrics.Counter
|
lostCounter metrics.Counter
|
||||||
dupeCounter metrics.Counter
|
dupeCounter metrics.Counter
|
||||||
outOfWindowCounter metrics.Counter
|
outOfWindowCounter metrics.Counter
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewBits(length uint64) *Bits {
|
func NewBits(bits uint64) *Bits {
|
||||||
if length == 0 || length&(length-1) != 0 {
|
|
||||||
panic(fmt.Sprintf("Bits length must be a power of two, got %d", length))
|
|
||||||
}
|
|
||||||
|
|
||||||
nWords := length / bitsPerWord
|
|
||||||
if nWords == 0 {
|
|
||||||
nWords = 1
|
|
||||||
}
|
|
||||||
b := &Bits{
|
b := &Bits{
|
||||||
length: length,
|
length: bits,
|
||||||
lengthMask: length - 1,
|
bits: make([]bool, bits, bits),
|
||||||
bits: make([]uint64, nWords),
|
|
||||||
current: 0,
|
current: 0,
|
||||||
lostCounter: metrics.GetOrRegisterCounter("network.packets.lost", nil),
|
lostCounter: metrics.GetOrRegisterCounter("network.packets.lost", nil),
|
||||||
dupeCounter: metrics.GetOrRegisterCounter("network.packets.duplicate", nil),
|
dupeCounter: metrics.GetOrRegisterCounter("network.packets.duplicate", nil),
|
||||||
@@ -45,194 +27,71 @@ func NewBits(length uint64) *Bits {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// There is no counter value 0, mark it to avoid counting a lost packet later.
|
// There is no counter value 0, mark it to avoid counting a lost packet later.
|
||||||
b.bits[0] = 1
|
b.bits[0] = true
|
||||||
|
b.current = 0
|
||||||
return b
|
return b
|
||||||
}
|
}
|
||||||
|
|
||||||
func (b *Bits) get(i uint64) bool {
|
|
||||||
pos := i & b.lengthMask
|
|
||||||
//bit-shifting by 6 because i is a bit index, not a u64 index, and we need to find the u64 without bit in it
|
|
||||||
return b.bits[pos>>6]&(uint64(1)<<(pos&63)) != 0
|
|
||||||
}
|
|
||||||
|
|
||||||
func (b *Bits) set(i uint64) {
|
|
||||||
pos := i & b.lengthMask
|
|
||||||
b.bits[pos>>6] |= uint64(1) << (pos & 63)
|
|
||||||
}
|
|
||||||
|
|
||||||
// clearRange clears `count` bits starting at circular position `startPos`
|
|
||||||
// (already masked to [0, length)) and returns how many of them were set
|
|
||||||
// before the clear. count must be in [1, length].
|
|
||||||
func (b *Bits) clearRange(startPos, count uint64) uint64 {
|
|
||||||
wasSet := uint64(0)
|
|
||||||
if count >= b.length {
|
|
||||||
for _, w := range b.bits {
|
|
||||||
wasSet += uint64(mathbits.OnesCount64(w))
|
|
||||||
}
|
|
||||||
clear(b.bits)
|
|
||||||
return wasSet
|
|
||||||
}
|
|
||||||
|
|
||||||
pos := startPos
|
|
||||||
remaining := count
|
|
||||||
|
|
||||||
// handle the potential partial word before pos becomes u64 aligned
|
|
||||||
word := pos >> 6
|
|
||||||
bit := pos & 63
|
|
||||||
take := uint64(64) - bit
|
|
||||||
if take > remaining {
|
|
||||||
take = remaining
|
|
||||||
}
|
|
||||||
if take > b.length-pos {
|
|
||||||
take = b.length - pos
|
|
||||||
}
|
|
||||||
var mask uint64
|
|
||||||
if take == 64 {
|
|
||||||
mask = math.MaxUint64
|
|
||||||
} else {
|
|
||||||
mask = ((uint64(1) << take) - 1) << bit
|
|
||||||
}
|
|
||||||
wasSet += uint64(mathbits.OnesCount64(b.bits[word] & mask))
|
|
||||||
b.bits[word] &^= mask
|
|
||||||
remaining -= take
|
|
||||||
pos = (pos + take) & b.lengthMask
|
|
||||||
|
|
||||||
// Clear whole words, keeping track of the number of set bits
|
|
||||||
for remaining >= 64 {
|
|
||||||
word = pos >> 6
|
|
||||||
wasSet += uint64(mathbits.OnesCount64(b.bits[word]))
|
|
||||||
b.bits[word] = 0
|
|
||||||
remaining -= 64
|
|
||||||
pos = (pos + 64) & b.lengthMask
|
|
||||||
}
|
|
||||||
|
|
||||||
// Clear the remaining partial word
|
|
||||||
if remaining > 0 {
|
|
||||||
word = pos >> 6
|
|
||||||
mask = (uint64(1) << remaining) - 1
|
|
||||||
wasSet += uint64(mathbits.OnesCount64(b.bits[word] & mask))
|
|
||||||
b.bits[word] &^= mask
|
|
||||||
}
|
|
||||||
|
|
||||||
return wasSet
|
|
||||||
}
|
|
||||||
|
|
||||||
func (b *Bits) strictlyWithinWindow(i uint64) bool {
|
|
||||||
// Handle the case where the window hasn't slid yet. This avoids u64 underflow.
|
|
||||||
inWarmup := b.current < b.length
|
|
||||||
if i < b.length && inWarmup {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
// Next, if the packet is in-window, see if we've seen it before
|
|
||||||
if i > b.current-b.length {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
return false //not within window!
|
|
||||||
}
|
|
||||||
|
|
||||||
// Check returns true if i is within (or way out in front of) the window, and not a replay
|
|
||||||
func (b *Bits) Check(l *slog.Logger, i uint64) bool {
|
func (b *Bits) Check(l *slog.Logger, i uint64) bool {
|
||||||
// If i is the next number, return true.
|
// If i is the next number, return true.
|
||||||
if i > b.current {
|
if i > b.current {
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
if b.strictlyWithinWindow(i) {
|
// If i is within the window, check if it's been set already.
|
||||||
return !b.get(i)
|
if i > b.current-b.length || i < b.length && b.current < b.length {
|
||||||
|
return !b.bits[i%b.length]
|
||||||
}
|
}
|
||||||
|
|
||||||
// Not within the window
|
// Not within the window
|
||||||
if l.Enabled(context.Background(), slog.LevelDebug) {
|
if l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
l.Debug("rejected a packet (top)", "current", b.current, "incoming", i)
|
l.Debug("rejected a packet (top)",
|
||||||
|
"current", b.current,
|
||||||
|
"incoming", i,
|
||||||
|
)
|
||||||
}
|
}
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
// Update has three branches:
|
|
||||||
// - i == b.current+1: fast path; advance the cursor by one and lose-count
|
|
||||||
// the slot we just stomped (only past warmup; see the i > b.length guard
|
|
||||||
// below).
|
|
||||||
// - i > b.current+1: jump path; clear all slots between current and i
|
|
||||||
// (or up to a full window's worth, whichever is smaller) via clearRange,
|
|
||||||
// then mark i. Two arms here: a warmup arm that handles the very first
|
|
||||||
// window before the cursor has slid, and a steady-state arm that treats
|
|
||||||
// every cleared empty slot as a lost packet.
|
|
||||||
// - i <= b.current: in-window check for duplicates; out-of-window otherwise.
|
|
||||||
//
|
|
||||||
// NewBits seeds bits[0]=1 so counter 0 looks "received" — Update never
|
|
||||||
// clears that marker during warmup (clearRange skips position 0 when
|
|
||||||
// startPos=1), and once b.current >= b.length the marker is no longer
|
|
||||||
// consulted. The marker prevents a fictitious "lost" hit on the first real
|
|
||||||
// counter.
|
|
||||||
func (b *Bits) Update(l *slog.Logger, i uint64) bool {
|
func (b *Bits) Update(l *slog.Logger, i uint64) bool {
|
||||||
// Fast path: i is the next expected counter. Split out so the function
|
// If i is the next number, return true and update current.
|
||||||
// stays small and avoids paying for the slow paths' slog argument-build
|
|
||||||
// stack frame on every call. The bit read/test/write is inlined to
|
|
||||||
// touch the backing word once.
|
|
||||||
if i == b.current+1 {
|
if i == b.current+1 {
|
||||||
pos := i & b.lengthMask
|
// Check if the oldest bit was lost since we are shifting the window by 1 and occupying it with this counter
|
||||||
word := pos >> 6
|
// The very first window can only be tracked as lost once we are on the 2nd window or greater
|
||||||
mask := uint64(1) << (pos & 63)
|
if b.bits[i%b.length] == false && i > b.length {
|
||||||
w := b.bits[word]
|
|
||||||
if i > b.length && w&mask == 0 {
|
|
||||||
b.lostCounter.Inc(1)
|
b.lostCounter.Inc(1)
|
||||||
}
|
}
|
||||||
b.bits[word] = w | mask
|
b.bits[i%b.length] = true
|
||||||
b.current = i
|
b.current = i
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
return b.updateSlow(l, i)
|
|
||||||
}
|
|
||||||
|
|
||||||
// updateSlow handles jumps, in-window backfill, dupes, and out-of-window.
|
|
||||||
func (b *Bits) updateSlow(l *slog.Logger, i uint64) bool {
|
|
||||||
// If i is a jump, adjust the window, record lost, update current, and return true
|
// If i is a jump, adjust the window, record lost, update current, and return true
|
||||||
if i > b.current {
|
if i > b.current {
|
||||||
end := i
|
lost := int64(0)
|
||||||
if end > b.current+b.length {
|
// Zero out the bits between the current and the new counter value, limited by the window size,
|
||||||
end = b.current + b.length
|
// since the window is shifting
|
||||||
}
|
for n := b.current + 1; n <= min(i, b.current+b.length); n++ {
|
||||||
count := end - b.current
|
if b.bits[n%b.length] == false && n > b.length {
|
||||||
startPos := (b.current + 1) & b.lengthMask
|
lost++
|
||||||
|
|
||||||
var lost int64
|
|
||||||
if b.current >= b.length {
|
|
||||||
// Steady state: every cleared slot is past warmup, so any unset
|
|
||||||
// bit we evict is a lost packet from the previous cycle.
|
|
||||||
wasSet := b.clearRange(startPos, count)
|
|
||||||
lost = int64(count) - int64(wasSet)
|
|
||||||
} else {
|
|
||||||
// Warmup (the very first window). Some cleared slots represent
|
|
||||||
// packets <= length where eviction is not "lost" in the usual
|
|
||||||
// sense. This branch is taken at most once per connection so we
|
|
||||||
// don't bother optimizing it.
|
|
||||||
for n := b.current + 1; n <= end; n++ {
|
|
||||||
if !b.get(n) && n > b.length {
|
|
||||||
lost++
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
b.clearRange(startPos, count)
|
b.bits[n%b.length] = false
|
||||||
}
|
}
|
||||||
|
|
||||||
// Anything past the new window can never be backfilled, so it's lost.
|
// Only record any skipped packets as a result of the window moving further than the window length
|
||||||
if i > b.current+b.length {
|
// Any loss within the new window will be accounted for in future calls
|
||||||
lost += int64(i - b.current - b.length)
|
lost += max(0, int64(i-b.current-b.length))
|
||||||
}
|
|
||||||
b.lostCounter.Inc(lost)
|
b.lostCounter.Inc(lost)
|
||||||
|
|
||||||
b.set(i)
|
b.bits[i%b.length] = true
|
||||||
b.current = i
|
b.current = i
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
// If i is within the current window but below the current counter, check to see if it's a duplicate
|
// If i is within the current window but below the current counter,
|
||||||
if b.strictlyWithinWindow(i) {
|
// Check to see if it's a duplicate
|
||||||
pos := i & b.lengthMask
|
if i > b.current-b.length || i < b.length && b.current < b.length {
|
||||||
word := pos >> 6
|
if b.current == i || b.bits[i%b.length] == true {
|
||||||
mask := uint64(1) << (pos & 63)
|
|
||||||
w := b.bits[word]
|
|
||||||
if b.current == i || w&mask != 0 {
|
|
||||||
if l.Enabled(context.Background(), slog.LevelDebug) {
|
if l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
l.Debug("Receive window",
|
l.Debug("Receive window",
|
||||||
"accepted", false,
|
"accepted", false,
|
||||||
@@ -245,7 +104,7 @@ func (b *Bits) updateSlow(l *slog.Logger, i uint64) bool {
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
b.bits[word] = w | mask
|
b.bits[i%b.length] = true
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+129
-276
@@ -7,79 +7,61 @@ import (
|
|||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
)
|
)
|
||||||
|
|
||||||
// snapshot returns the bitmap as a []bool of length b.length, for readable
|
|
||||||
// test assertions against the now-packed []uint64 storage.
|
|
||||||
func (b *Bits) snapshot() []bool {
|
|
||||||
out := make([]bool, b.length)
|
|
||||||
for i := uint64(0); i < b.length; i++ {
|
|
||||||
out[i] = b.get(i)
|
|
||||||
}
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestBitsRequiresPowerOfTwo(t *testing.T) {
|
|
||||||
assert.Panics(t, func() { NewBits(10) })
|
|
||||||
assert.Panics(t, func() { NewBits(0) })
|
|
||||||
assert.NotPanics(t, func() { NewBits(1) })
|
|
||||||
assert.NotPanics(t, func() { NewBits(16) })
|
|
||||||
assert.NotPanics(t, func() { NewBits(1024) })
|
|
||||||
assert.NotPanics(t, func() { NewBits(16384) })
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestBits(t *testing.T) {
|
func TestBits(t *testing.T) {
|
||||||
l := test.NewLogger()
|
l := test.NewLogger()
|
||||||
b := NewBits(16)
|
b := NewBits(10)
|
||||||
assert.EqualValues(t, 16, b.length)
|
|
||||||
|
// make sure it is the right size
|
||||||
|
assert.Len(t, b.bits, 10)
|
||||||
|
|
||||||
// This is initialized to zero - receive one. This should work.
|
// This is initialized to zero - receive one. This should work.
|
||||||
assert.True(t, b.Check(l, 1))
|
assert.True(t, b.Check(l, 1))
|
||||||
assert.True(t, b.Update(l, 1))
|
assert.True(t, b.Update(l, 1))
|
||||||
assert.EqualValues(t, 1, b.current)
|
assert.EqualValues(t, 1, b.current)
|
||||||
g := []bool{true, true, false, false, false, false, false, false, false, false, false, false, false, false, false, false}
|
g := []bool{true, true, false, false, false, false, false, false, false, false}
|
||||||
assert.Equal(t, g, b.snapshot())
|
assert.Equal(t, g, b.bits)
|
||||||
|
|
||||||
// Receive two
|
// Receive two
|
||||||
assert.True(t, b.Check(l, 2))
|
assert.True(t, b.Check(l, 2))
|
||||||
assert.True(t, b.Update(l, 2))
|
assert.True(t, b.Update(l, 2))
|
||||||
assert.EqualValues(t, 2, b.current)
|
assert.EqualValues(t, 2, b.current)
|
||||||
g = []bool{true, true, true, false, false, false, false, false, false, false, false, false, false, false, false, false}
|
g = []bool{true, true, true, false, false, false, false, false, false, false}
|
||||||
assert.Equal(t, g, b.snapshot())
|
assert.Equal(t, g, b.bits)
|
||||||
|
|
||||||
// Receive two again - it will fail
|
// Receive two again - it will fail
|
||||||
assert.False(t, b.Check(l, 2))
|
assert.False(t, b.Check(l, 2))
|
||||||
assert.False(t, b.Update(l, 2))
|
assert.False(t, b.Update(l, 2))
|
||||||
assert.EqualValues(t, 2, b.current)
|
assert.EqualValues(t, 2, b.current)
|
||||||
|
|
||||||
// Jump ahead to 25, which clears the window and sets slot 25%16 = 9.
|
// Jump ahead to 15, which should clear everything and set the 6th element
|
||||||
assert.True(t, b.Check(l, 25))
|
assert.True(t, b.Check(l, 15))
|
||||||
assert.True(t, b.Update(l, 25))
|
assert.True(t, b.Update(l, 15))
|
||||||
assert.EqualValues(t, 25, b.current)
|
assert.EqualValues(t, 15, b.current)
|
||||||
g = []bool{false, false, false, false, false, false, false, false, false, true, false, false, false, false, false, false}
|
g = []bool{false, false, false, false, false, true, false, false, false, false}
|
||||||
assert.Equal(t, g, b.snapshot())
|
assert.Equal(t, g, b.bits)
|
||||||
|
|
||||||
// Mark 24, which is in window (current 25, length 16, window covers [10,25]).
|
// Mark 14, which is allowed because it is in the window
|
||||||
assert.True(t, b.Check(l, 24))
|
assert.True(t, b.Check(l, 14))
|
||||||
assert.True(t, b.Update(l, 24))
|
assert.True(t, b.Update(l, 14))
|
||||||
assert.EqualValues(t, 25, b.current)
|
assert.EqualValues(t, 15, b.current)
|
||||||
g = []bool{false, false, false, false, false, false, false, false, true, true, false, false, false, false, false, false}
|
g = []bool{false, false, false, false, true, true, false, false, false, false}
|
||||||
assert.Equal(t, g, b.snapshot())
|
assert.Equal(t, g, b.bits)
|
||||||
|
|
||||||
// Mark 5, not allowed because 5 <= current-length (25-16=9).
|
// Mark 5, which is not allowed because it is not in the window
|
||||||
assert.False(t, b.Check(l, 5))
|
assert.False(t, b.Check(l, 5))
|
||||||
assert.False(t, b.Update(l, 5))
|
assert.False(t, b.Update(l, 5))
|
||||||
assert.EqualValues(t, 25, b.current)
|
assert.EqualValues(t, 15, b.current)
|
||||||
g = []bool{false, false, false, false, false, false, false, false, true, true, false, false, false, false, false, false}
|
g = []bool{false, false, false, false, true, true, false, false, false, false}
|
||||||
assert.Equal(t, g, b.snapshot())
|
assert.Equal(t, g, b.bits)
|
||||||
|
|
||||||
// Make sure we handle wrapping around once to the same slot. With
|
// make sure we handle wrapping around once to the current position
|
||||||
// length=16, packets 1 and 17 share slot 1.
|
b = NewBits(10)
|
||||||
b = NewBits(16)
|
|
||||||
assert.True(t, b.Update(l, 1))
|
assert.True(t, b.Update(l, 1))
|
||||||
assert.True(t, b.Update(l, 17))
|
assert.True(t, b.Update(l, 11))
|
||||||
assert.Equal(t, []bool{false, true, false, false, false, false, false, false, false, false, false, false, false, false, false, false}, b.snapshot())
|
assert.Equal(t, []bool{false, true, false, false, false, false, false, false, false, false}, b.bits)
|
||||||
|
|
||||||
// Walk through a few windows in order
|
// Walk through a few windows in order
|
||||||
b = NewBits(16)
|
b = NewBits(10)
|
||||||
for i := uint64(1); i <= 100; i++ {
|
for i := uint64(1); i <= 100; i++ {
|
||||||
assert.True(t, b.Check(l, i), "Error while checking %v", i)
|
assert.True(t, b.Check(l, i), "Error while checking %v", i)
|
||||||
assert.True(t, b.Update(l, i), "Error while updating %v", i)
|
assert.True(t, b.Update(l, i), "Error while updating %v", i)
|
||||||
@@ -90,31 +72,24 @@ func TestBits(t *testing.T) {
|
|||||||
|
|
||||||
func TestBitsLargeJumps(t *testing.T) {
|
func TestBitsLargeJumps(t *testing.T) {
|
||||||
l := test.NewLogger()
|
l := test.NewLogger()
|
||||||
|
b := NewBits(10)
|
||||||
// length=16. Update(55) from current=0:
|
|
||||||
// warmup, per-bit loop sees no n>16 with unset bits (slot 0 was set by
|
|
||||||
// NewBits and gets re-evaluated when n=16; n=16 is not strictly > 16),
|
|
||||||
// so the loop contributes 0. The jump exceeds the window so we record
|
|
||||||
// 55 - 0 - 16 = 39 packets fell out the back.
|
|
||||||
b := NewBits(16)
|
|
||||||
b.lostCounter.Clear()
|
b.lostCounter.Clear()
|
||||||
assert.True(t, b.Update(l, 55))
|
|
||||||
assert.Equal(t, int64(39), b.lostCounter.Count())
|
|
||||||
|
|
||||||
// Update(100): clears 16 slots starting at slot 56%16=8. Only slot 7 (for
|
b = NewBits(10)
|
||||||
// packet 55) was set, so 16 - 1 = 15 evicted slots had unset bits.
|
b.lostCounter.Clear()
|
||||||
// Plus 100 - 55 - 16 = 29 packets fell past the window. Total 44.
|
assert.True(t, b.Update(l, 55)) // We saw packet 55 and can still track 45,46,47,48,49,50,51,52,53,54
|
||||||
assert.True(t, b.Update(l, 100))
|
assert.Equal(t, int64(45), b.lostCounter.Count())
|
||||||
assert.Equal(t, int64(39+44), b.lostCounter.Count())
|
|
||||||
|
|
||||||
// Update(200): same shape: 16 - 1 = 15 evicted unset, plus 200 - 100 - 16 = 84 past window. Total 99.
|
assert.True(t, b.Update(l, 100)) // We saw packet 55 and 100 and can still track 90,91,92,93,94,95,96,97,98,99
|
||||||
assert.True(t, b.Update(l, 200))
|
assert.Equal(t, int64(89), b.lostCounter.Count())
|
||||||
assert.Equal(t, int64(39+44+99), b.lostCounter.Count())
|
|
||||||
|
assert.True(t, b.Update(l, 200)) // We saw packet 55, 100, and 200 and can still track 190,191,192,193,194,195,196,197,198,199
|
||||||
|
assert.Equal(t, int64(188), b.lostCounter.Count())
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestBitsDupeCounter(t *testing.T) {
|
func TestBitsDupeCounter(t *testing.T) {
|
||||||
l := test.NewLogger()
|
l := test.NewLogger()
|
||||||
b := NewBits(16)
|
b := NewBits(10)
|
||||||
b.lostCounter.Clear()
|
b.lostCounter.Clear()
|
||||||
b.dupeCounter.Clear()
|
b.dupeCounter.Clear()
|
||||||
b.outOfWindowCounter.Clear()
|
b.outOfWindowCounter.Clear()
|
||||||
@@ -139,117 +114,120 @@ func TestBitsDupeCounter(t *testing.T) {
|
|||||||
|
|
||||||
func TestBitsOutOfWindowCounter(t *testing.T) {
|
func TestBitsOutOfWindowCounter(t *testing.T) {
|
||||||
l := test.NewLogger()
|
l := test.NewLogger()
|
||||||
b := NewBits(16)
|
b := NewBits(10)
|
||||||
b.lostCounter.Clear()
|
b.lostCounter.Clear()
|
||||||
b.dupeCounter.Clear()
|
b.dupeCounter.Clear()
|
||||||
b.outOfWindowCounter.Clear()
|
b.outOfWindowCounter.Clear()
|
||||||
|
|
||||||
// Jump to 20 (warmup branch + 4 past-window packets).
|
|
||||||
assert.True(t, b.Update(l, 20))
|
assert.True(t, b.Update(l, 20))
|
||||||
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
||||||
|
|
||||||
// 9 single-step advances, each evicts a slot whose bit was cleared during
|
assert.True(t, b.Update(l, 21))
|
||||||
// the jump above and whose value was never seen, so each contributes 1
|
assert.True(t, b.Update(l, 22))
|
||||||
// to lostCounter.
|
assert.True(t, b.Update(l, 23))
|
||||||
for n := uint64(21); n <= 29; n++ {
|
assert.True(t, b.Update(l, 24))
|
||||||
assert.True(t, b.Update(l, n))
|
assert.True(t, b.Update(l, 25))
|
||||||
}
|
assert.True(t, b.Update(l, 26))
|
||||||
|
assert.True(t, b.Update(l, 27))
|
||||||
|
assert.True(t, b.Update(l, 28))
|
||||||
|
assert.True(t, b.Update(l, 29))
|
||||||
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
||||||
|
|
||||||
// 0 is below current-length (29-16=13) so it falls outside the window.
|
|
||||||
assert.False(t, b.Update(l, 0))
|
assert.False(t, b.Update(l, 0))
|
||||||
assert.Equal(t, int64(1), b.outOfWindowCounter.Count())
|
assert.Equal(t, int64(1), b.outOfWindowCounter.Count())
|
||||||
|
|
||||||
// 4 from the Update(20) jump + 9 from 21..29.
|
assert.Equal(t, int64(19), b.lostCounter.Count()) // packet 0 wasn't lost
|
||||||
assert.Equal(t, int64(13), b.lostCounter.Count())
|
|
||||||
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
||||||
assert.Equal(t, int64(1), b.outOfWindowCounter.Count())
|
assert.Equal(t, int64(1), b.outOfWindowCounter.Count())
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestBitsLostCounter(t *testing.T) {
|
func TestBitsLostCounter(t *testing.T) {
|
||||||
l := test.NewLogger()
|
l := test.NewLogger()
|
||||||
b := NewBits(16)
|
b := NewBits(10)
|
||||||
b.lostCounter.Clear()
|
b.lostCounter.Clear()
|
||||||
b.dupeCounter.Clear()
|
b.dupeCounter.Clear()
|
||||||
b.outOfWindowCounter.Clear()
|
b.outOfWindowCounter.Clear()
|
||||||
|
|
||||||
// Walk 20..29 like the original, just with a bigger window. Same
|
assert.True(t, b.Update(l, 20))
|
||||||
// reasoning as TestBitsOutOfWindowCounter: 4 past-window from Update(20),
|
assert.True(t, b.Update(l, 21))
|
||||||
// then 9 more from the unit advances.
|
assert.True(t, b.Update(l, 22))
|
||||||
for n := uint64(20); n <= 29; n++ {
|
assert.True(t, b.Update(l, 23))
|
||||||
assert.True(t, b.Update(l, n))
|
assert.True(t, b.Update(l, 24))
|
||||||
}
|
assert.True(t, b.Update(l, 25))
|
||||||
assert.Equal(t, int64(13), b.lostCounter.Count())
|
assert.True(t, b.Update(l, 26))
|
||||||
|
assert.True(t, b.Update(l, 27))
|
||||||
|
assert.True(t, b.Update(l, 28))
|
||||||
|
assert.True(t, b.Update(l, 29))
|
||||||
|
assert.Equal(t, int64(19), b.lostCounter.Count()) // packet 0 wasn't lost
|
||||||
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
||||||
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
||||||
|
|
||||||
b = NewBits(16)
|
b = NewBits(10)
|
||||||
b.lostCounter.Clear()
|
b.lostCounter.Clear()
|
||||||
b.dupeCounter.Clear()
|
b.dupeCounter.Clear()
|
||||||
b.outOfWindowCounter.Clear()
|
b.outOfWindowCounter.Clear()
|
||||||
|
|
||||||
// Update(15) clears the warmup window (no lost), sets slot 15.
|
assert.True(t, b.Update(l, 9))
|
||||||
assert.True(t, b.Update(l, 15))
|
|
||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
assert.Equal(t, int64(0), b.lostCounter.Count())
|
||||||
|
// 10 will set 0 index, 0 was already set, no lost packets
|
||||||
// Update(16): slot 0 was already set (NewBits seeded it), and 16 is not
|
assert.True(t, b.Update(l, 10))
|
||||||
// strictly > length, so nothing is recorded as lost.
|
|
||||||
assert.True(t, b.Update(l, 16))
|
|
||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
assert.Equal(t, int64(0), b.lostCounter.Count())
|
||||||
|
// 11 will set 1 index, 1 was missed, we should see 1 packet lost
|
||||||
// Update(17): we jumped straight from 0 to 15, so slot 1 was cleared
|
assert.True(t, b.Update(l, 11))
|
||||||
// (and never re-set). 17 > 16 is past warmup, so packet 1 is recorded lost.
|
|
||||||
assert.True(t, b.Update(l, 17))
|
|
||||||
assert.Equal(t, int64(1), b.lostCounter.Count())
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
|
// Now let's fill in the window, should end up with 8 lost packets
|
||||||
|
assert.True(t, b.Update(l, 12))
|
||||||
|
assert.True(t, b.Update(l, 13))
|
||||||
|
assert.True(t, b.Update(l, 14))
|
||||||
|
assert.True(t, b.Update(l, 15))
|
||||||
|
assert.True(t, b.Update(l, 16))
|
||||||
|
assert.True(t, b.Update(l, 17))
|
||||||
|
assert.True(t, b.Update(l, 18))
|
||||||
|
assert.True(t, b.Update(l, 19))
|
||||||
|
assert.Equal(t, int64(8), b.lostCounter.Count())
|
||||||
|
|
||||||
// Fill in 18..30 in single steps. Each i evicts slot i%16. Slots 2..14
|
// Jump ahead by a window size
|
||||||
// were all cleared during Update(15), and we never re-set any of them,
|
assert.True(t, b.Update(l, 29))
|
||||||
// so each i in 18..30 is a fresh lost packet — 13 more.
|
assert.Equal(t, int64(8), b.lostCounter.Count())
|
||||||
for n := uint64(18); n <= 30; n++ {
|
// Now lets walk ahead normally through the window, the missed packets should fill in
|
||||||
assert.True(t, b.Update(l, n))
|
assert.True(t, b.Update(l, 30))
|
||||||
}
|
assert.True(t, b.Update(l, 31))
|
||||||
assert.Equal(t, int64(14), b.lostCounter.Count())
|
assert.True(t, b.Update(l, 32))
|
||||||
|
assert.True(t, b.Update(l, 33))
|
||||||
|
assert.True(t, b.Update(l, 34))
|
||||||
|
assert.True(t, b.Update(l, 35))
|
||||||
|
assert.True(t, b.Update(l, 36))
|
||||||
|
assert.True(t, b.Update(l, 37))
|
||||||
|
assert.True(t, b.Update(l, 38))
|
||||||
|
// 39 packets tracked, 22 seen, 17 lost
|
||||||
|
assert.Equal(t, int64(17), b.lostCounter.Count())
|
||||||
|
|
||||||
// Jump ahead by exactly one window size.
|
// Jump ahead by 2 windows, should have recording 1 full window missing
|
||||||
assert.True(t, b.Update(l, 46))
|
assert.True(t, b.Update(l, 58))
|
||||||
// end = min(46, 30+16) = 46, count = 16, all slots cleared. Before the
|
assert.Equal(t, int64(27), b.lostCounter.Count())
|
||||||
// jump every slot 0..15 had been set (Update(15), (16), (17), 18..30),
|
// Now lets walk ahead normally through the window, the missed packets should fill in from this window
|
||||||
// so wasSet=16 and 46 == current+length means no past-window slack:
|
assert.True(t, b.Update(l, 59))
|
||||||
// lost contribution = 0.
|
assert.True(t, b.Update(l, 60))
|
||||||
assert.Equal(t, int64(14), b.lostCounter.Count())
|
assert.True(t, b.Update(l, 61))
|
||||||
|
assert.True(t, b.Update(l, 62))
|
||||||
// Walk 47..55. The Update(46) jump cleared every slot, so only slot 14
|
assert.True(t, b.Update(l, 63))
|
||||||
// (for packet 46) is set when we start. Each subsequent unit step lands
|
assert.True(t, b.Update(l, 64))
|
||||||
// on a slot that was cleared and is past warmup, so it counts as lost.
|
assert.True(t, b.Update(l, 65))
|
||||||
// 9 more = 23.
|
assert.True(t, b.Update(l, 66))
|
||||||
for n := uint64(47); n <= 55; n++ {
|
assert.True(t, b.Update(l, 67))
|
||||||
assert.True(t, b.Update(l, n))
|
// 68 packets tracked, 32 seen, 36 missed
|
||||||
}
|
assert.Equal(t, int64(36), b.lostCounter.Count())
|
||||||
assert.Equal(t, int64(23), b.lostCounter.Count())
|
|
||||||
|
|
||||||
// Jump ahead by two windows: clears the window plus past-window loss.
|
|
||||||
assert.True(t, b.Update(l, 87))
|
|
||||||
// current=55, length=16. end = min(87, 71) = 71. count=16, all slots
|
|
||||||
// cleared. Slots set before the clear are slots 14,15,0..7 (10 total).
|
|
||||||
// Lost from clear = 16 - 10 = 6. Past window: 87 - 55 - 16 = 16. +22.
|
|
||||||
assert.Equal(t, int64(45), b.lostCounter.Count())
|
|
||||||
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
||||||
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestBitsLostCounterIssue1(t *testing.T) {
|
func TestBitsLostCounterIssue1(t *testing.T) {
|
||||||
l := test.NewLogger()
|
l := test.NewLogger()
|
||||||
b := NewBits(16)
|
b := NewBits(10)
|
||||||
b.lostCounter.Clear()
|
b.lostCounter.Clear()
|
||||||
b.dupeCounter.Clear()
|
b.dupeCounter.Clear()
|
||||||
b.outOfWindowCounter.Clear()
|
b.outOfWindowCounter.Clear()
|
||||||
|
|
||||||
// Receive 4, backfill 1, then 9, 2, 3, 5, 6, 7 (skip 8), 10, 11, 14.
|
|
||||||
// Then jump to 25 — slot 25%16=9 is being evicted, but it had been set
|
|
||||||
// (we received packet 9), so no spurious lost increment. The original
|
|
||||||
// regression was about double-counting a missing packet when its slot
|
|
||||||
// got cleared on a jump. With the jump path now using clearRange's
|
|
||||||
// word-level wasSet count, the same semantics hold.
|
|
||||||
assert.True(t, b.Update(l, 4))
|
assert.True(t, b.Update(l, 4))
|
||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
assert.Equal(t, int64(0), b.lostCounter.Count())
|
||||||
assert.True(t, b.Update(l, 1))
|
assert.True(t, b.Update(l, 1))
|
||||||
@@ -266,7 +244,7 @@ func TestBitsLostCounterIssue1(t *testing.T) {
|
|||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
assert.Equal(t, int64(0), b.lostCounter.Count())
|
||||||
assert.True(t, b.Update(l, 7))
|
assert.True(t, b.Update(l, 7))
|
||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
assert.Equal(t, int64(0), b.lostCounter.Count())
|
||||||
// Skip packet 8.
|
// assert.True(t, b.Update(l, 8))
|
||||||
assert.True(t, b.Update(l, 10))
|
assert.True(t, b.Update(l, 10))
|
||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
assert.Equal(t, int64(0), b.lostCounter.Count())
|
||||||
assert.True(t, b.Update(l, 11))
|
assert.True(t, b.Update(l, 11))
|
||||||
@@ -274,23 +252,9 @@ func TestBitsLostCounterIssue1(t *testing.T) {
|
|||||||
|
|
||||||
assert.True(t, b.Update(l, 14))
|
assert.True(t, b.Update(l, 14))
|
||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
assert.Equal(t, int64(0), b.lostCounter.Count())
|
||||||
|
// Issue seems to be here, we reset missing packet 8 to false here and don't increment the lost counter
|
||||||
// Jump to 25. With length=16, slot 25%16=9 corresponds to packet 9
|
assert.True(t, b.Update(l, 19))
|
||||||
// (which we DID receive), so its bit is set and no lost++ from that
|
|
||||||
// eviction. The trace below shows the only loss is packet 8.
|
|
||||||
assert.True(t, b.Update(l, 25))
|
|
||||||
// current was 14, i=25. end=min(25,30)=25. count=11. startPos=15.
|
|
||||||
// steady? current=14<16, so warmup branch: per-bit n=15..25, count those
|
|
||||||
// with !get(n) AND n>16. n=17..25 are >16. Among slots 17%16=1..25%16=9
|
|
||||||
// did we set slots 1..9 (packets 1..9)? Yes for all but slot 8 (packet 8
|
|
||||||
// was skipped). n=24 maps to slot 8 which is FALSE → lost++. All other
|
|
||||||
// n in 17..25 map to slots that are set. n=16 is not strictly > 16. So
|
|
||||||
// lost = 1.
|
|
||||||
assert.Equal(t, int64(1), b.lostCounter.Count())
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
|
|
||||||
// Fill in 12, 13, 15, 16. Each is below current=25 (in-window). 16 must
|
|
||||||
// recheck slot 0 — it was set by NewBits and then cleared by the
|
|
||||||
// Update(25) jump, so 16 backfills cleanly.
|
|
||||||
assert.True(t, b.Update(l, 12))
|
assert.True(t, b.Update(l, 12))
|
||||||
assert.Equal(t, int64(1), b.lostCounter.Count())
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
assert.True(t, b.Update(l, 13))
|
assert.True(t, b.Update(l, 13))
|
||||||
@@ -299,140 +263,29 @@ func TestBitsLostCounterIssue1(t *testing.T) {
|
|||||||
assert.Equal(t, int64(1), b.lostCounter.Count())
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
assert.True(t, b.Update(l, 16))
|
assert.True(t, b.Update(l, 16))
|
||||||
assert.Equal(t, int64(1), b.lostCounter.Count())
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
|
assert.True(t, b.Update(l, 17))
|
||||||
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
|
assert.True(t, b.Update(l, 18))
|
||||||
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
|
assert.True(t, b.Update(l, 20))
|
||||||
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
|
assert.True(t, b.Update(l, 21))
|
||||||
|
|
||||||
// We missed packet 8 above and that loss is still recorded once, never
|
// We missed packet 8 above
|
||||||
// double-counted, never zeroed.
|
|
||||||
assert.Equal(t, int64(1), b.lostCounter.Count())
|
assert.Equal(t, int64(1), b.lostCounter.Count())
|
||||||
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
assert.Equal(t, int64(0), b.dupeCounter.Count())
|
||||||
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
assert.Equal(t, int64(0), b.outOfWindowCounter.Count())
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestBitsWarmupOvershoot exercises the jump path's warmup arm with an
|
func BenchmarkBits(b *testing.B) {
|
||||||
// overshoot past one full window. NewBits leaves current=0 with only slot 0
|
z := NewBits(10)
|
||||||
// "set" by the marker. Jumping straight to length+k must (a) clear every
|
|
||||||
// slot the jump straddles, (b) count only past-window slack (not the
|
|
||||||
// in-window slots, which never had a "lost" tenant during warmup), and
|
|
||||||
// (c) leave the cursor at the new counter so subsequent unit advances
|
|
||||||
// count from steady state. The marker bit at slot 0 is irrelevant once
|
|
||||||
// current >= length.
|
|
||||||
func TestBitsWarmupOvershoot(t *testing.T) {
|
|
||||||
l := test.NewLogger()
|
|
||||||
b := NewBits(16)
|
|
||||||
b.lostCounter.Clear()
|
|
||||||
|
|
||||||
// Jump from current=0 to i=20 (length=16, overshoot=4).
|
|
||||||
// Warmup arm: counts slots in [1..16] where bit unset and n>length.
|
|
||||||
// Only n=16 was unset and >length: but slot 16%16=0 is the marker,
|
|
||||||
// so b.get(16) reads bits[0]=1 and skips. Result: 0 lost from the loop.
|
|
||||||
// Past-window: i - current - length = 20 - 0 - 16 = 4 lost.
|
|
||||||
assert.True(t, b.Update(l, 20))
|
|
||||||
assert.Equal(t, int64(4), b.lostCounter.Count())
|
|
||||||
assert.Equal(t, uint64(20), b.current)
|
|
||||||
|
|
||||||
// Steady state now (current=20 >= length=16). Unit advance to 21
|
|
||||||
// stomps slot 21%16=5, which was cleared by the jump and not reset,
|
|
||||||
// so this is +1 lost.
|
|
||||||
assert.True(t, b.Update(l, 21))
|
|
||||||
assert.Equal(t, int64(5), b.lostCounter.Count())
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestBitsCheckAcrossWarmupBoundary pins the underflow trick in Check's
|
|
||||||
// in-window clause. While in warmup, b.current-b.length underflows uint64
|
|
||||||
// to a huge value so the first OR-clause is always false; the second
|
|
||||||
// clause (i < length && current < length) carries the in-window check.
|
|
||||||
// Once current >= length the regimes flip cleanly.
|
|
||||||
func TestBitsCheckAcrossWarmupBoundary(t *testing.T) {
|
|
||||||
l := test.NewLogger()
|
|
||||||
b := NewBits(16)
|
|
||||||
|
|
||||||
// Warmup: current=0. Check(0) must read the marker (set) and return false.
|
|
||||||
assert.False(t, b.Check(l, 0), "marker slot should look already-received")
|
|
||||||
// Warmup: any 0 < i < length is in-window and unset → accepted.
|
|
||||||
for i := uint64(1); i < 16; i++ {
|
|
||||||
assert.True(t, b.Check(l, i), "warmup in-window i=%d should be accepted", i)
|
|
||||||
}
|
|
||||||
// Warmup: i >= length but > current is "next number" so accepted.
|
|
||||||
assert.True(t, b.Check(l, 16))
|
|
||||||
assert.True(t, b.Check(l, 1_000_000))
|
|
||||||
|
|
||||||
// Cross into steady state.
|
|
||||||
assert.True(t, b.Update(l, 100))
|
|
||||||
// Now current=100, length=16. In-window range is [85..100].
|
|
||||||
// 84 is just outside: the underflow clause activates; 84 > 100-16=84 is false.
|
|
||||||
// And the warmup clause is false (current >= length). So out of window.
|
|
||||||
assert.False(t, b.Check(l, 84))
|
|
||||||
// 85 sits at the boundary. 85 > 84 is true → in window, unset → accept.
|
|
||||||
assert.True(t, b.Check(l, 85))
|
|
||||||
// 100 is current itself; not strictly greater, in-window, but already set.
|
|
||||||
assert.False(t, b.Check(l, 100))
|
|
||||||
// Way out: clearly out of window.
|
|
||||||
assert.False(t, b.Check(l, 50))
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestBitsMarkerInvariant verifies the seeded bits[0]=1 marker behaves
|
|
||||||
// correctly across warmup and beyond. Update should never clear the marker
|
|
||||||
// during warmup (clearRange skips position 0 when startPos=1), and once
|
|
||||||
// current >= length the marker is no longer consulted by Check/Update on
|
|
||||||
// the live path — but it must still report counter 0 as a duplicate while
|
|
||||||
// we are in warmup.
|
|
||||||
func TestBitsMarkerInvariant(t *testing.T) {
|
|
||||||
l := test.NewLogger()
|
|
||||||
b := NewBits(8)
|
|
||||||
|
|
||||||
// Counter 0 is the seeded marker; Check sees it as already received.
|
|
||||||
assert.False(t, b.Check(l, 0))
|
|
||||||
// Update(0) at current=0 hits the duplicate branch.
|
|
||||||
b.dupeCounter.Clear()
|
|
||||||
assert.False(t, b.Update(l, 0))
|
|
||||||
assert.Equal(t, int64(1), b.dupeCounter.Count())
|
|
||||||
|
|
||||||
// Walk forward through warmup; the marker must remain set.
|
|
||||||
for n := uint64(1); n <= 7; n++ {
|
|
||||||
assert.True(t, b.Update(l, n))
|
|
||||||
}
|
|
||||||
// Position 0 (the marker) should still read as set because we never
|
|
||||||
// cleared it; Update(0) still looks like a duplicate.
|
|
||||||
assert.False(t, b.Check(l, 0))
|
|
||||||
|
|
||||||
// Cross into steady state with a unit advance to 8: pos=0, evicts the
|
|
||||||
// marker bit. The lost-counter guard (i > b.length) is false (8 == 8),
|
|
||||||
// so this advance does NOT charge a lost packet — exactly what the
|
|
||||||
// marker is there to prevent.
|
|
||||||
b.lostCounter.Clear()
|
|
||||||
assert.True(t, b.Update(l, 8))
|
|
||||||
assert.Equal(t, int64(0), b.lostCounter.Count())
|
|
||||||
// The slot at pos 0 is now occupied by counter 8.
|
|
||||||
assert.False(t, b.Check(l, 8))
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkBitsUpdateInOrder is the steady-state hot path: each call is
|
|
||||||
// i == current+1.
|
|
||||||
func BenchmarkBitsUpdateInOrder(b *testing.B) {
|
|
||||||
l := test.NewLogger()
|
|
||||||
z := NewBits(16384)
|
|
||||||
for n := 0; n < b.N; n++ {
|
for n := 0; n < b.N; n++ {
|
||||||
z.Update(l, uint64(n)+1)
|
for i := range z.bits {
|
||||||
}
|
z.bits[i] = true
|
||||||
}
|
}
|
||||||
|
for i := range z.bits {
|
||||||
|
z.bits[i] = false
|
||||||
|
}
|
||||||
|
|
||||||
// BenchmarkBitsUpdateReorder simulates light reorder within the window:
|
|
||||||
// every other packet arrives one slot behind its predecessor (forces the
|
|
||||||
// in-window backfill branch).
|
|
||||||
func BenchmarkBitsUpdateReorder(b *testing.B) {
|
|
||||||
l := test.NewLogger()
|
|
||||||
z := NewBits(16384)
|
|
||||||
for n := 0; n < b.N; n++ {
|
|
||||||
base := uint64(n) * 2
|
|
||||||
z.Update(l, base+2)
|
|
||||||
z.Update(l, base+1)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkBitsUpdateLargeJumps stresses the clearRange word-level path.
|
|
||||||
func BenchmarkBitsUpdateLargeJumps(b *testing.B) {
|
|
||||||
l := test.NewLogger()
|
|
||||||
z := NewBits(16384)
|
|
||||||
for n := 0; n < b.N; n++ {
|
|
||||||
z.Update(l, uint64(n+1)*1000)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -217,10 +217,6 @@ func (ncp *CAPool) verify(c Certificate, now time.Time, certFp string, signerFp
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
if signer.Certificate.Curve() != c.Curve() {
|
|
||||||
return nil, ErrCurveMismatch
|
|
||||||
}
|
|
||||||
|
|
||||||
if signer.Certificate.Expired(now) {
|
if signer.Certificate.Expired(now) {
|
||||||
return nil, ErrRootExpired
|
return nil, ErrRootExpired
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -654,31 +654,3 @@ func TestCertificateV2_Verify_Subnets(t *testing.T) {
|
|||||||
_, err = caPool.VerifyCertificate(time.Now(), c)
|
_, err = caPool.VerifyCertificate(time.Now(), c)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestCertificateV2_CurveMismatch(t *testing.T) {
|
|
||||||
caIp1 := mustParsePrefixUnmapped("10.0.0.0/16")
|
|
||||||
caIp2 := mustParsePrefixUnmapped("192.168.0.0/24")
|
|
||||||
ca, _, caKey, _ := NewTestCaCert(Version2, Curve_P256, time.Now(), time.Now().Add(10*time.Minute), []netip.Prefix{caIp1, caIp2}, nil, []string{"test"})
|
|
||||||
|
|
||||||
caPem, err := ca.MarshalPEM()
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
caPool := NewCAPool()
|
|
||||||
b, err := caPool.AddCAFromPEM(caPem)
|
|
||||||
require.NoError(t, err)
|
|
||||||
assert.Empty(t, b)
|
|
||||||
|
|
||||||
// ip is outside the network
|
|
||||||
cIp1 := mustParsePrefixUnmapped("10.0.0.1/24")
|
|
||||||
c, _, _, _ := NewTestCert(Version2, Curve_P256, ca, caKey, "test", time.Now(), time.Now().Add(5*time.Minute), []netip.Prefix{cIp1}, nil, []string{"test"})
|
|
||||||
|
|
||||||
fp, _ := c.Fingerprint()
|
|
||||||
_, err = caPool.verify(c, time.Now(), fp, c.Issuer())
|
|
||||||
require.NoError(t, err)
|
|
||||||
//
|
|
||||||
c2 := c.(*certificateV2)
|
|
||||||
c2.curve = Curve_CURVE25519
|
|
||||||
fp, _ = c.Fingerprint()
|
|
||||||
_, err = caPool.verify(c, time.Now(), fp, c.Issuer())
|
|
||||||
require.Error(t, err)
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -112,9 +112,6 @@ func (c *certificateV1) CheckSignature(key []byte) bool {
|
|||||||
}
|
}
|
||||||
switch c.details.curve {
|
switch c.details.curve {
|
||||||
case Curve_CURVE25519:
|
case Curve_CURVE25519:
|
||||||
if len(key) != ed25519.PublicKeySize {
|
|
||||||
return false //avoids a panic internal to ed25519
|
|
||||||
}
|
|
||||||
return ed25519.Verify(key, b, c.signature)
|
return ed25519.Verify(key, b, c.signature)
|
||||||
case Curve_P256:
|
case Curve_P256:
|
||||||
pubKey, err := ecdsa.ParseUncompressedPublicKey(elliptic.P256(), key)
|
pubKey, err := ecdsa.ParseUncompressedPublicKey(elliptic.P256(), key)
|
||||||
|
|||||||
@@ -151,9 +151,6 @@ func (c *certificateV2) CheckSignature(key []byte) bool {
|
|||||||
|
|
||||||
switch c.curve {
|
switch c.curve {
|
||||||
case Curve_CURVE25519:
|
case Curve_CURVE25519:
|
||||||
if len(key) != ed25519.PublicKeySize {
|
|
||||||
return false //avoids a panic internal to ed25519
|
|
||||||
}
|
|
||||||
return ed25519.Verify(key, b, c.signature)
|
return ed25519.Verify(key, b, c.signature)
|
||||||
case Curve_P256:
|
case Curve_P256:
|
||||||
pubKey, err := ecdsa.ParseUncompressedPublicKey(elliptic.P256(), key)
|
pubKey, err := ecdsa.ParseUncompressedPublicKey(elliptic.P256(), key)
|
||||||
|
|||||||
@@ -22,7 +22,6 @@ var (
|
|||||||
ErrCaNotFound = errors.New("could not find ca for the certificate")
|
ErrCaNotFound = errors.New("could not find ca for the certificate")
|
||||||
ErrUnknownVersion = errors.New("certificate version unrecognized")
|
ErrUnknownVersion = errors.New("certificate version unrecognized")
|
||||||
ErrCertPubkeyPresent = errors.New("certificate has unexpected pubkey present")
|
ErrCertPubkeyPresent = errors.New("certificate has unexpected pubkey present")
|
||||||
ErrCurveMismatch = errors.New("certificate curve does not match CA")
|
|
||||||
|
|
||||||
ErrInvalidPEMBlock = errors.New("input did not contain a valid PEM encoded block")
|
ErrInvalidPEMBlock = errors.New("input did not contain a valid PEM encoded block")
|
||||||
ErrInvalidPEMCertificateBanner = errors.New("bytes did not contain a proper certificate banner")
|
ErrInvalidPEMCertificateBanner = errors.New("bytes did not contain a proper certificate banner")
|
||||||
|
|||||||
+52
-13
@@ -11,6 +11,7 @@ import (
|
|||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"github.com/rcrowley/go-metrics"
|
||||||
"github.com/slackhq/nebula/cert"
|
"github.com/slackhq/nebula/cert"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/header"
|
"github.com/slackhq/nebula/header"
|
||||||
@@ -44,16 +45,19 @@ type connectionManager struct {
|
|||||||
inactivityTimeout atomic.Int64
|
inactivityTimeout atomic.Int64
|
||||||
dropInactive atomic.Bool
|
dropInactive atomic.Bool
|
||||||
|
|
||||||
|
metricsTxPunchy metrics.Counter
|
||||||
|
|
||||||
l *slog.Logger
|
l *slog.Logger
|
||||||
}
|
}
|
||||||
|
|
||||||
func newConnectionManagerFromConfig(l *slog.Logger, c *config.C, hm *HostMap, p *Punchy) *connectionManager {
|
func newConnectionManagerFromConfig(l *slog.Logger, c *config.C, hm *HostMap, p *Punchy) *connectionManager {
|
||||||
cm := &connectionManager{
|
cm := &connectionManager{
|
||||||
hostMap: hm,
|
hostMap: hm,
|
||||||
l: l,
|
l: l,
|
||||||
punchy: p,
|
punchy: p,
|
||||||
relayUsed: make(map[uint32]struct{}),
|
relayUsed: make(map[uint32]struct{}),
|
||||||
relayUsedLock: &sync.RWMutex{},
|
relayUsedLock: &sync.RWMutex{},
|
||||||
|
metricsTxPunchy: metrics.GetOrRegisterCounter("messages.tx.punchy", nil),
|
||||||
}
|
}
|
||||||
|
|
||||||
cm.reload(c, true)
|
cm.reload(c, true)
|
||||||
@@ -141,6 +145,7 @@ func (cm *connectionManager) getAndResetTrafficCheck(h *HostInfo, now time.Time)
|
|||||||
func (cm *connectionManager) AddTrafficWatch(h *HostInfo) {
|
func (cm *connectionManager) AddTrafficWatch(h *HostInfo) {
|
||||||
if h.out.Swap(true) == false {
|
if h.out.Swap(true) == false {
|
||||||
cm.trafficTimer.Add(h.localIndexId, cm.checkInterval)
|
cm.trafficTimer.Add(h.localIndexId, cm.checkInterval)
|
||||||
|
cm.intf.pmtudManager.OnTunnelUp(h)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -176,6 +181,7 @@ func (cm *connectionManager) doTrafficCheck(localIndex uint32, p, nb, out []byte
|
|||||||
|
|
||||||
switch decision {
|
switch decision {
|
||||||
case deleteTunnel:
|
case deleteTunnel:
|
||||||
|
cm.intf.pmtudManager.OnTunnelDown(hostinfo)
|
||||||
if cm.hostMap.DeleteHostInfo(hostinfo) {
|
if cm.hostMap.DeleteHostInfo(hostinfo) {
|
||||||
// Only clearing the lighthouse cache if this is the last hostinfo for this vpn ip in the hostmap
|
// Only clearing the lighthouse cache if this is the last hostinfo for this vpn ip in the hostmap
|
||||||
cm.intf.lightHouse.DeleteVpnAddrs(hostinfo.vpnAddrs)
|
cm.intf.lightHouse.DeleteVpnAddrs(hostinfo.vpnAddrs)
|
||||||
@@ -195,7 +201,14 @@ func (cm *connectionManager) doTrafficCheck(localIndex uint32, p, nb, out []byte
|
|||||||
cm.tryRehandshake(hostinfo)
|
cm.tryRehandshake(hostinfo)
|
||||||
|
|
||||||
case sendTestPacket:
|
case sendTestPacket:
|
||||||
cm.intf.SendMessageToHostInfo(header.Test, header.TestRequest, hostinfo, p, nb, out)
|
// Defer to pmtud if it has a confirmed PMTU > floor for this peer:
|
||||||
|
// the probe at the confirmed size verifies both liveness AND that
|
||||||
|
// the discovered PMTU still fits, so we don't burn a separate test
|
||||||
|
// packet on top of it. If pmtud declines (disabled, peer unsupported,
|
||||||
|
// or no confirmed size yet) we fall back to the regular test.
|
||||||
|
if !cm.intf.pmtudManager.MaybeProbeAsTest(hostinfo) {
|
||||||
|
cm.intf.SendMessageToHostInfo(header.Test, header.TestRequest, hostinfo, p, nb, out)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
cm.resetRelayTrafficCheck(hostinfo)
|
cm.resetRelayTrafficCheck(hostinfo)
|
||||||
@@ -365,7 +378,7 @@ func (cm *connectionManager) makeTrafficDecision(localIndex uint32, now time.Tim
|
|||||||
|
|
||||||
if !outTraffic {
|
if !outTraffic {
|
||||||
// Send a punch packet to keep the NAT state alive
|
// Send a punch packet to keep the NAT state alive
|
||||||
cm.punchy.SendPunch(hostinfo)
|
cm.sendPunch(hostinfo)
|
||||||
}
|
}
|
||||||
|
|
||||||
return decision, hostinfo, primary
|
return decision, hostinfo, primary
|
||||||
@@ -396,16 +409,17 @@ func (cm *connectionManager) makeTrafficDecision(localIndex uint32, now time.Tim
|
|||||||
|
|
||||||
// If we aren't sending or receiving traffic then its an unused tunnel and we don't to test the tunnel.
|
// If we aren't sending or receiving traffic then its an unused tunnel and we don't to test the tunnel.
|
||||||
// Just maintain NAT state if configured to do so.
|
// Just maintain NAT state if configured to do so.
|
||||||
cm.punchy.SendPunch(hostinfo)
|
cm.sendPunch(hostinfo)
|
||||||
cm.trafficTimer.Add(hostinfo.localIndexId, cm.checkInterval)
|
cm.trafficTimer.Add(hostinfo.localIndexId, cm.checkInterval)
|
||||||
return doNothing, nil, nil
|
return doNothing, nil, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// We aren't receiving traffic but we are sending it. The outbound
|
if cm.punchy.GetTargetEverything() {
|
||||||
// traffic itself refreshes the primary remote's NAT state; this
|
// This is similar to the old punchy behavior with a slight optimization.
|
||||||
// fans out to non-primary remotes, but only if target_all_remotes
|
// We aren't receiving traffic but we are sending it, punch on all known
|
||||||
// is configured.
|
// ips in case we need to re-prime NAT state
|
||||||
cm.punchy.SendPunchToAll(hostinfo)
|
cm.sendPunch(hostinfo)
|
||||||
|
}
|
||||||
|
|
||||||
if cm.l.Enabled(context.Background(), slog.LevelDebug) {
|
if cm.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
hostinfo.logger(cm.l).Debug("Tunnel status",
|
hostinfo.logger(cm.l).Debug("Tunnel status",
|
||||||
@@ -507,6 +521,31 @@ func (cm *connectionManager) isInvalidCertificate(now time.Time, hostinfo *HostI
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (cm *connectionManager) sendPunch(hostinfo *HostInfo) {
|
||||||
|
if !cm.punchy.GetPunch() {
|
||||||
|
// Punching is disabled
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if cm.intf.lightHouse.IsAnyLighthouseAddr(hostinfo.vpnAddrs) {
|
||||||
|
// Do not punch to lighthouses, we assume our lighthouse update interval is good enough.
|
||||||
|
// In the event the update interval is not sufficient to maintain NAT state then a publicly available lighthouse
|
||||||
|
// would lose the ability to notify us and punchy.respond would become unreliable.
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if cm.punchy.GetTargetEverything() {
|
||||||
|
hostinfo.remotes.ForEach(cm.hostMap.GetPreferredRanges(), func(addr netip.AddrPort, preferred bool) {
|
||||||
|
cm.metricsTxPunchy.Inc(1)
|
||||||
|
cm.intf.outside.WriteTo([]byte{1}, addr)
|
||||||
|
})
|
||||||
|
|
||||||
|
} else if hostinfo.remote.IsValid() {
|
||||||
|
cm.metricsTxPunchy.Inc(1)
|
||||||
|
cm.intf.outside.WriteTo([]byte{1}, hostinfo.remote)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (cm *connectionManager) tryRehandshake(hostinfo *HostInfo) {
|
func (cm *connectionManager) tryRehandshake(hostinfo *HostInfo) {
|
||||||
cs := cm.intf.pki.getCertState()
|
cs := cm.intf.pki.getCertState()
|
||||||
curCrt := hostinfo.ConnectionState.myCert
|
curCrt := hostinfo.ConnectionState.myCert
|
||||||
|
|||||||
@@ -64,9 +64,11 @@ func Test_NewConnectionManagerTest(t *testing.T) {
|
|||||||
|
|
||||||
// Create manager
|
// Create manager
|
||||||
conf := config.NewC(test.NewLogger())
|
conf := config.NewC(test.NewLogger())
|
||||||
punchy := NewPunchyFromConfig(test.NewLogger(), conf, nil)
|
punchy := NewPunchyFromConfig(test.NewLogger(), conf)
|
||||||
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
||||||
nc.intf = ifce
|
nc.intf = ifce
|
||||||
|
ifce.pmtudManager = newPMTUDManagerFromConfig(test.NewLogger(), conf, ifce.inside)
|
||||||
|
ifce.pmtudManager.intf = ifce
|
||||||
p := []byte("")
|
p := []byte("")
|
||||||
nb := make([]byte, 12, 12)
|
nb := make([]byte, 12, 12)
|
||||||
out := make([]byte, mtu)
|
out := make([]byte, mtu)
|
||||||
@@ -146,9 +148,11 @@ func Test_NewConnectionManagerTest2(t *testing.T) {
|
|||||||
|
|
||||||
// Create manager
|
// Create manager
|
||||||
conf := config.NewC(test.NewLogger())
|
conf := config.NewC(test.NewLogger())
|
||||||
punchy := NewPunchyFromConfig(test.NewLogger(), conf, nil)
|
punchy := NewPunchyFromConfig(test.NewLogger(), conf)
|
||||||
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
||||||
nc.intf = ifce
|
nc.intf = ifce
|
||||||
|
ifce.pmtudManager = newPMTUDManagerFromConfig(test.NewLogger(), conf, ifce.inside)
|
||||||
|
ifce.pmtudManager.intf = ifce
|
||||||
p := []byte("")
|
p := []byte("")
|
||||||
nb := make([]byte, 12, 12)
|
nb := make([]byte, 12, 12)
|
||||||
out := make([]byte, mtu)
|
out := make([]byte, mtu)
|
||||||
@@ -233,7 +237,7 @@ func Test_NewConnectionManager_DisconnectInactive(t *testing.T) {
|
|||||||
conf.Settings["tunnels"] = map[string]any{
|
conf.Settings["tunnels"] = map[string]any{
|
||||||
"drop_inactive": true,
|
"drop_inactive": true,
|
||||||
}
|
}
|
||||||
punchy := NewPunchyFromConfig(test.NewLogger(), conf, nil)
|
punchy := NewPunchyFromConfig(test.NewLogger(), conf)
|
||||||
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
||||||
assert.True(t, nc.dropInactive.Load())
|
assert.True(t, nc.dropInactive.Load())
|
||||||
nc.intf = ifce
|
nc.intf = ifce
|
||||||
@@ -358,9 +362,11 @@ func Test_NewConnectionManagerTest_DisconnectInvalid(t *testing.T) {
|
|||||||
|
|
||||||
// Create manager
|
// Create manager
|
||||||
conf := config.NewC(test.NewLogger())
|
conf := config.NewC(test.NewLogger())
|
||||||
punchy := NewPunchyFromConfig(test.NewLogger(), conf, nil)
|
punchy := NewPunchyFromConfig(test.NewLogger(), conf)
|
||||||
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
nc := newConnectionManagerFromConfig(test.NewLogger(), conf, hostMap, punchy)
|
||||||
nc.intf = ifce
|
nc.intf = ifce
|
||||||
|
ifce.pmtudManager = newPMTUDManagerFromConfig(test.NewLogger(), conf, ifce.inside)
|
||||||
|
ifce.pmtudManager.intf = ifce
|
||||||
ifce.connectionManager = nc
|
ifce.connectionManager = nc
|
||||||
|
|
||||||
hostinfo := &HostInfo{
|
hostinfo := &HostInfo{
|
||||||
|
|||||||
+5
-6
@@ -7,14 +7,13 @@ import (
|
|||||||
|
|
||||||
"github.com/slackhq/nebula/cert"
|
"github.com/slackhq/nebula/cert"
|
||||||
"github.com/slackhq/nebula/handshake"
|
"github.com/slackhq/nebula/handshake"
|
||||||
"github.com/slackhq/nebula/noiseutil"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const ReplayWindow = 8192
|
const ReplayWindow = 1024
|
||||||
|
|
||||||
type ConnectionState struct {
|
type ConnectionState struct {
|
||||||
eKey noiseutil.CipherState
|
eKey *NebulaCipherState
|
||||||
dKey noiseutil.CipherState
|
dKey *NebulaCipherState
|
||||||
myCert cert.Certificate
|
myCert cert.Certificate
|
||||||
peerCert *cert.CachedCertificate
|
peerCert *cert.CachedCertificate
|
||||||
initiator bool
|
initiator bool
|
||||||
@@ -32,8 +31,8 @@ func newConnectionStateFromResult(r *handshake.Result) *ConnectionState {
|
|||||||
myCert: r.MyCert,
|
myCert: r.MyCert,
|
||||||
initiator: r.Initiator,
|
initiator: r.Initiator,
|
||||||
peerCert: r.RemoteCert,
|
peerCert: r.RemoteCert,
|
||||||
eKey: noiseutil.NewCipherState(r.EKey, r.Cipher),
|
eKey: NewNebulaCipherState(r.EKey),
|
||||||
dKey: noiseutil.NewCipherState(r.DKey, r.Cipher),
|
dKey: NewNebulaCipherState(r.DKey),
|
||||||
window: NewBits(ReplayWindow),
|
window: NewBits(ReplayWindow),
|
||||||
}
|
}
|
||||||
ci.messageCounter.Add(r.MessageIndex)
|
ci.messageCounter.Add(r.MessageIndex)
|
||||||
|
|||||||
@@ -54,6 +54,7 @@ type Control struct {
|
|||||||
dnsStart func()
|
dnsStart func()
|
||||||
lighthouseStart func()
|
lighthouseStart func()
|
||||||
connectionManagerStart func(context.Context)
|
connectionManagerStart func(context.Context)
|
||||||
|
pmtudManagerStart func(context.Context)
|
||||||
}
|
}
|
||||||
|
|
||||||
type ControlHostInfo struct {
|
type ControlHostInfo struct {
|
||||||
@@ -107,6 +108,9 @@ func (c *Control) Start() (func() error, error) {
|
|||||||
if c.connectionManagerStart != nil {
|
if c.connectionManagerStart != nil {
|
||||||
go c.connectionManagerStart(c.ctx)
|
go c.connectionManagerStart(c.ctx)
|
||||||
}
|
}
|
||||||
|
if c.pmtudManagerStart != nil {
|
||||||
|
go c.pmtudManagerStart(c.ctx)
|
||||||
|
}
|
||||||
if c.lighthouseStart != nil {
|
if c.lighthouseStart != nil {
|
||||||
c.lighthouseStart()
|
c.lighthouseStart()
|
||||||
}
|
}
|
||||||
|
|||||||
+60
-12
@@ -5,6 +5,8 @@ package nebula
|
|||||||
import (
|
import (
|
||||||
"net/netip"
|
"net/netip"
|
||||||
|
|
||||||
|
"github.com/google/gopacket"
|
||||||
|
"github.com/google/gopacket/layers"
|
||||||
"github.com/slackhq/nebula/header"
|
"github.com/slackhq/nebula/header"
|
||||||
"github.com/slackhq/nebula/overlay"
|
"github.com/slackhq/nebula/overlay"
|
||||||
"github.com/slackhq/nebula/udp"
|
"github.com/slackhq/nebula/udp"
|
||||||
@@ -20,9 +22,7 @@ func (c *Control) WaitForType(msgType header.MessageType, subType header.Message
|
|||||||
panic(err)
|
panic(err)
|
||||||
}
|
}
|
||||||
pipeTo.InjectUDPPacket(p)
|
pipeTo.InjectUDPPacket(p)
|
||||||
match := h.Type == msgType && h.Subtype == subType
|
if h.Type == msgType && h.Subtype == subType {
|
||||||
p.Release()
|
|
||||||
if match {
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -38,9 +38,7 @@ func (c *Control) WaitForTypeByIndex(toIndex uint32, msgType header.MessageType,
|
|||||||
panic(err)
|
panic(err)
|
||||||
}
|
}
|
||||||
pipeTo.InjectUDPPacket(p)
|
pipeTo.InjectUDPPacket(p)
|
||||||
match := h.RemoteIndex == toIndex && h.Type == msgType && h.Subtype == subType
|
if h.RemoteIndex == toIndex && h.Type == msgType && h.Subtype == subType {
|
||||||
p.Release()
|
|
||||||
if match {
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -92,15 +90,65 @@ func (c *Control) GetTunTxChan() <-chan []byte {
|
|||||||
return c.f.inside.(*overlay.TestTun).TxPackets
|
return c.f.inside.(*overlay.TestTun).TxPackets
|
||||||
}
|
}
|
||||||
|
|
||||||
// InjectUDPPacket injects a packet into the udp side. We copy internally so the caller keeps ownership of p.
|
// InjectUDPPacket will inject a packet into the udp side of nebula
|
||||||
// The copy comes from the freelist so steady-state alloc is zero.
|
|
||||||
func (c *Control) InjectUDPPacket(p *udp.Packet) {
|
func (c *Control) InjectUDPPacket(p *udp.Packet) {
|
||||||
c.f.outside.(*udp.TesterConn).Send(p.Copy())
|
c.f.outside.(*udp.TesterConn).Send(p)
|
||||||
}
|
}
|
||||||
|
|
||||||
// InjectTunPacket pushes an IP packet onto the tun interface.
|
// InjectTunUDPPacket puts a udp packet on the tun interface. Using UDP here because it's a simpler protocol
|
||||||
func (c *Control) InjectTunPacket(packet []byte) {
|
func (c *Control) InjectTunUDPPacket(toAddr netip.Addr, toPort uint16, fromAddr netip.Addr, fromPort uint16, data []byte) {
|
||||||
c.f.inside.(*overlay.TestTun).Send(packet)
|
serialize := make([]gopacket.SerializableLayer, 0)
|
||||||
|
var netLayer gopacket.NetworkLayer
|
||||||
|
if toAddr.Is6() {
|
||||||
|
if !fromAddr.Is6() {
|
||||||
|
panic("Cant send ipv6 to ipv4")
|
||||||
|
}
|
||||||
|
ip := &layers.IPv6{
|
||||||
|
Version: 6,
|
||||||
|
NextHeader: layers.IPProtocolUDP,
|
||||||
|
SrcIP: fromAddr.Unmap().AsSlice(),
|
||||||
|
DstIP: toAddr.Unmap().AsSlice(),
|
||||||
|
}
|
||||||
|
serialize = append(serialize, ip)
|
||||||
|
netLayer = ip
|
||||||
|
} else {
|
||||||
|
if !fromAddr.Is4() {
|
||||||
|
panic("Cant send ipv4 to ipv6")
|
||||||
|
}
|
||||||
|
|
||||||
|
ip := &layers.IPv4{
|
||||||
|
Version: 4,
|
||||||
|
TTL: 64,
|
||||||
|
Protocol: layers.IPProtocolUDP,
|
||||||
|
SrcIP: fromAddr.Unmap().AsSlice(),
|
||||||
|
DstIP: toAddr.Unmap().AsSlice(),
|
||||||
|
}
|
||||||
|
serialize = append(serialize, ip)
|
||||||
|
netLayer = ip
|
||||||
|
}
|
||||||
|
|
||||||
|
udp := layers.UDP{
|
||||||
|
SrcPort: layers.UDPPort(fromPort),
|
||||||
|
DstPort: layers.UDPPort(toPort),
|
||||||
|
}
|
||||||
|
err := udp.SetNetworkLayerForChecksum(netLayer)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
buffer := gopacket.NewSerializeBuffer()
|
||||||
|
opt := gopacket.SerializeOptions{
|
||||||
|
ComputeChecksums: true,
|
||||||
|
FixLengths: true,
|
||||||
|
}
|
||||||
|
|
||||||
|
serialize = append(serialize, &udp, gopacket.Payload(data))
|
||||||
|
err = gopacket.SerializeLayers(buffer, opt, serialize...)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
c.f.inside.(*overlay.TestTun).Send(buffer.Bytes())
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *Control) GetVpnAddrs() []netip.Addr {
|
func (c *Control) GetVpnAddrs() []netip.Addr {
|
||||||
|
|||||||
@@ -47,7 +47,7 @@ func TestHandshakeRetransmitDuplicate(t *testing.T) {
|
|||||||
defer r.RenderFlow()
|
defer r.RenderFlow()
|
||||||
|
|
||||||
t.Log("Trigger handshake from me to them")
|
t.Log("Trigger handshake from me to them")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi"))
|
||||||
|
|
||||||
t.Log("Grab my msg1")
|
t.Log("Grab my msg1")
|
||||||
msg1 := myControl.GetFromUDP(true)
|
msg1 := myControl.GetFromUDP(true)
|
||||||
@@ -97,7 +97,7 @@ func TestHandshakeTruncatedPacketRecovery(t *testing.T) {
|
|||||||
defer r.RenderFlow()
|
defer r.RenderFlow()
|
||||||
|
|
||||||
t.Log("Trigger handshake")
|
t.Log("Trigger handshake")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi"))
|
||||||
|
|
||||||
t.Log("Get msg1 and deliver to responder")
|
t.Log("Get msg1 and deliver to responder")
|
||||||
msg1 := myControl.GetFromUDP(true)
|
msg1 := myControl.GetFromUDP(true)
|
||||||
@@ -146,7 +146,7 @@ func TestHandshakeOrphanedMsg2Dropped(t *testing.T) {
|
|||||||
defer r.RenderFlow()
|
defer r.RenderFlow()
|
||||||
|
|
||||||
t.Log("Complete a normal handshake")
|
t.Log("Complete a normal handshake")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi"))
|
||||||
r.RouteForAllUntilTxTun(theirControl)
|
r.RouteForAllUntilTxTun(theirControl)
|
||||||
assertTunnel(t, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), myControl, theirControl, r)
|
assertTunnel(t, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), myControl, theirControl, r)
|
||||||
|
|
||||||
@@ -248,7 +248,7 @@ func TestHandshakeLateResponse(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger handshake from me")
|
t.Log("Trigger handshake from me")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi"))
|
||||||
|
|
||||||
t.Log("Grab msg1 but don't deliver")
|
t.Log("Grab msg1 but don't deliver")
|
||||||
msg1 := myControl.GetFromUDP(true)
|
msg1 := myControl.GetFromUDP(true)
|
||||||
@@ -292,7 +292,7 @@ func TestHandshakeSelfConnectionRejected(t *testing.T) {
|
|||||||
myControl.Start()
|
myControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger handshake from me")
|
t.Log("Trigger handshake from me")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(netip.MustParseAddr("10.128.0.2"), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi")))
|
myControl.InjectTunUDPPacket(netip.MustParseAddr("10.128.0.2"), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi"))
|
||||||
msg1 := myControl.GetFromUDP(true)
|
msg1 := myControl.GetFromUDP(true)
|
||||||
|
|
||||||
t.Log("Drain any handshake retransmits before injecting")
|
t.Log("Drain any handshake retransmits before injecting")
|
||||||
@@ -375,7 +375,7 @@ func TestHandshakeRemoteAllowList(t *testing.T) {
|
|||||||
defer r.RenderFlow()
|
defer r.RenderFlow()
|
||||||
|
|
||||||
t.Log("Trigger handshake from them")
|
t.Log("Trigger handshake from them")
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi"))
|
||||||
msg1 := theirControl.GetFromUDP(true)
|
msg1 := theirControl.GetFromUDP(true)
|
||||||
|
|
||||||
t.Log("Rewrite the source to a blocked IP and inject")
|
t.Log("Rewrite the source to a blocked IP and inject")
|
||||||
@@ -426,7 +426,7 @@ func TestHandshakeAlreadySeenPreferredRemote(t *testing.T) {
|
|||||||
defer r.RenderFlow()
|
defer r.RenderFlow()
|
||||||
|
|
||||||
t.Log("Complete a normal handshake via the router")
|
t.Log("Complete a normal handshake via the router")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi"))
|
||||||
r.RouteForAllUntilTxTun(theirControl)
|
r.RouteForAllUntilTxTun(theirControl)
|
||||||
assertTunnel(t, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), myControl, theirControl, r)
|
assertTunnel(t, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), myControl, theirControl, r)
|
||||||
|
|
||||||
@@ -437,7 +437,7 @@ func TestHandshakeAlreadySeenPreferredRemote(t *testing.T) {
|
|||||||
originalRemote := hi.CurrentRemote
|
originalRemote := hi.CurrentRemote
|
||||||
|
|
||||||
t.Log("Re-trigger traffic to cause a new handshake attempt (ErrAlreadySeen)")
|
t.Log("Re-trigger traffic to cause a new handshake attempt (ErrAlreadySeen)")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("roam")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("roam"))
|
||||||
r.RouteForAllUntilTxTun(theirControl)
|
r.RouteForAllUntilTxTun(theirControl)
|
||||||
|
|
||||||
t.Log("Verify tunnel still works")
|
t.Log("Verify tunnel still works")
|
||||||
@@ -475,8 +475,8 @@ func TestHandshakeWrongResponderPacketStore(t *testing.T) {
|
|||||||
evilControl.Start()
|
evilControl.Start()
|
||||||
|
|
||||||
t.Log("Send multiple packets to them (cached during handshake)")
|
t.Log("Send multiple packets to them (cached during handshake)")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("packet1")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("packet1"))
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("packet2")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("packet2"))
|
||||||
|
|
||||||
t.Log("Route until evil tunnel is closed")
|
t.Log("Route until evil tunnel is closed")
|
||||||
h := &header.H{}
|
h := &header.H{}
|
||||||
@@ -540,7 +540,7 @@ func TestHandshakeRelayComplete(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger handshake via relay")
|
t.Log("Trigger handshake via relay")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi via relay")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi via relay"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
assertUdpPacket(t, []byte("Hi via relay"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi via relay"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
||||||
@@ -568,7 +568,7 @@ func TestHandshakeRelayComplete(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// NOTE: Relay V1 cert + IPv6 rejection is not tested here because
|
// NOTE: Relay V1 cert + IPv6 rejection is not tested here because
|
||||||
// BuildTunUDPPacket from a V4 node to a V6 address panics in the test
|
// InjectTunUDPPacket from a V4 node to a V6 address panics in the test
|
||||||
// framework. The check is in handshake_manager.go handleOutbound relay
|
// framework. The check is in handshake_manager.go handleOutbound relay
|
||||||
// logic (lines ~304-313): if the relay host has a V1 cert and either
|
// logic (lines ~304-313): if the relay host has a V1 cert and either
|
||||||
// address is IPv6, the relay is skipped.
|
// address is IPv6, the relay is skipped.
|
||||||
|
|||||||
+30
-46
@@ -16,7 +16,6 @@ import (
|
|||||||
"github.com/slackhq/nebula/cert_test"
|
"github.com/slackhq/nebula/cert_test"
|
||||||
"github.com/slackhq/nebula/e2e/router"
|
"github.com/slackhq/nebula/e2e/router"
|
||||||
"github.com/slackhq/nebula/header"
|
"github.com/slackhq/nebula/header"
|
||||||
"github.com/slackhq/nebula/overlay"
|
|
||||||
"github.com/slackhq/nebula/udp"
|
"github.com/slackhq/nebula/udp"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
"github.com/stretchr/testify/require"
|
"github.com/stretchr/testify/require"
|
||||||
@@ -40,22 +39,11 @@ func BenchmarkHotPath(b *testing.B) {
|
|||||||
r.CancelFlowLogs()
|
r.CancelFlowLogs()
|
||||||
|
|
||||||
assertTunnel(b, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), myControl, theirControl, r)
|
assertTunnel(b, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), myControl, theirControl, r)
|
||||||
|
|
||||||
// Pre-build the IP packet bytes once so the bench measures the data plane,
|
|
||||||
// not gopacket SerializeLayers overhead.
|
|
||||||
prebuilt := BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
|
||||||
|
|
||||||
// EnableFanIn switches the router to a 0-alloc routing path. Required
|
|
||||||
// for hot-path benchmarks; would conflict with GetFromUDP-using tests.
|
|
||||||
r.EnableFanIn()
|
|
||||||
|
|
||||||
b.ResetTimer()
|
b.ResetTimer()
|
||||||
|
|
||||||
for n := 0; n < b.N; n++ {
|
for n := 0; n < b.N; n++ {
|
||||||
myControl.InjectTunPacket(prebuilt)
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
// Release the TUN-side bytes back to the harness freelist; the bench
|
_ = r.RouteForAllUntilTxTun(theirControl)
|
||||||
// just confirms a packet arrived, the contents aren't inspected.
|
|
||||||
overlay.ReleaseTunBuf(r.RouteForAllUntilTxTun(theirControl))
|
|
||||||
}
|
}
|
||||||
|
|
||||||
myControl.Stop()
|
myControl.Stop()
|
||||||
@@ -83,15 +71,11 @@ func BenchmarkHotPathRelay(b *testing.B) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
assertTunnel(b, theirVpnIpNet[0].Addr(), myVpnIpNet[0].Addr(), theirControl, myControl, r)
|
assertTunnel(b, theirVpnIpNet[0].Addr(), myVpnIpNet[0].Addr(), theirControl, myControl, r)
|
||||||
|
|
||||||
prebuilt := BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
|
||||||
r.EnableFanIn()
|
|
||||||
|
|
||||||
b.ResetTimer()
|
b.ResetTimer()
|
||||||
|
|
||||||
for n := 0; n < b.N; n++ {
|
for n := 0; n < b.N; n++ {
|
||||||
myControl.InjectTunPacket(prebuilt)
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
overlay.ReleaseTunBuf(r.RouteForAllUntilTxTun(theirControl))
|
_ = r.RouteForAllUntilTxTun(theirControl)
|
||||||
}
|
}
|
||||||
|
|
||||||
myControl.Stop()
|
myControl.Stop()
|
||||||
@@ -113,7 +97,7 @@ func TestGoodHandshake(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Send a udp packet through to begin standing up the tunnel, this should come out the other side")
|
t.Log("Send a udp packet through to begin standing up the tunnel, this should come out the other side")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
t.Log("Have them consume my stage 0 packet. They have a tunnel now")
|
t.Log("Have them consume my stage 0 packet. They have a tunnel now")
|
||||||
theirControl.InjectUDPPacket(myControl.GetFromUDP(true))
|
theirControl.InjectUDPPacket(myControl.GetFromUDP(true))
|
||||||
@@ -207,7 +191,7 @@ func TestWrongResponderHandshake(t *testing.T) {
|
|||||||
evilControl.Start()
|
evilControl.Start()
|
||||||
|
|
||||||
t.Log("Start the handshake process, we will route until we see the evil tunnel closed")
|
t.Log("Start the handshake process, we will route until we see the evil tunnel closed")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
h := &header.H{}
|
h := &header.H{}
|
||||||
r.RouteForAllExitFunc(func(p *udp.Packet, c *nebula.Control) router.ExitType {
|
r.RouteForAllExitFunc(func(p *udp.Packet, c *nebula.Control) router.ExitType {
|
||||||
@@ -289,7 +273,7 @@ func TestWrongResponderHandshakeStaticHostMap(t *testing.T) {
|
|||||||
evilControl.Start()
|
evilControl.Start()
|
||||||
|
|
||||||
t.Log("Start the handshake process, we will route until we see the evil tunnel closed")
|
t.Log("Start the handshake process, we will route until we see the evil tunnel closed")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
h := &header.H{}
|
h := &header.H{}
|
||||||
r.RouteForAllExitFunc(func(p *udp.Packet, c *nebula.Control) router.ExitType {
|
r.RouteForAllExitFunc(func(p *udp.Packet, c *nebula.Control) router.ExitType {
|
||||||
@@ -368,8 +352,8 @@ func TestStage1Race(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger a handshake to start on both me and them")
|
t.Log("Trigger a handshake to start on both me and them")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them"))
|
||||||
|
|
||||||
t.Log("Get both stage 1 handshake packets")
|
t.Log("Get both stage 1 handshake packets")
|
||||||
myHsForThem := myControl.GetFromUDP(true)
|
myHsForThem := myControl.GetFromUDP(true)
|
||||||
@@ -446,7 +430,7 @@ func TestUncleanShutdownRaceLoser(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
r.Log("Trigger a handshake from me to them")
|
r.Log("Trigger a handshake from me to them")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
assertUdpPacket(t, []byte("Hi from me"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi from me"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
||||||
@@ -457,7 +441,7 @@ func TestUncleanShutdownRaceLoser(t *testing.T) {
|
|||||||
myHostmap.Indexes = map[uint32]*nebula.HostInfo{}
|
myHostmap.Indexes = map[uint32]*nebula.HostInfo{}
|
||||||
myHostmap.RemoteIndexes = map[uint32]*nebula.HostInfo{}
|
myHostmap.RemoteIndexes = map[uint32]*nebula.HostInfo{}
|
||||||
|
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me again")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me again"))
|
||||||
p = r.RouteForAllUntilTxTun(theirControl)
|
p = r.RouteForAllUntilTxTun(theirControl)
|
||||||
assertUdpPacket(t, []byte("Hi from me again"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi from me again"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
||||||
|
|
||||||
@@ -496,7 +480,7 @@ func TestUncleanShutdownRaceWinner(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
r.Log("Trigger a handshake from me to them")
|
r.Log("Trigger a handshake from me to them")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
assertUdpPacket(t, []byte("Hi from me"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi from me"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
||||||
@@ -508,7 +492,7 @@ func TestUncleanShutdownRaceWinner(t *testing.T) {
|
|||||||
theirHostmap.Indexes = map[uint32]*nebula.HostInfo{}
|
theirHostmap.Indexes = map[uint32]*nebula.HostInfo{}
|
||||||
theirHostmap.RemoteIndexes = map[uint32]*nebula.HostInfo{}
|
theirHostmap.RemoteIndexes = map[uint32]*nebula.HostInfo{}
|
||||||
|
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them again")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them again"))
|
||||||
p = r.RouteForAllUntilTxTun(myControl)
|
p = r.RouteForAllUntilTxTun(myControl)
|
||||||
assertUdpPacket(t, []byte("Hi from them again"), p, theirVpnIpNet[0].Addr(), myVpnIpNet[0].Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi from them again"), p, theirVpnIpNet[0].Addr(), myVpnIpNet[0].Addr(), 80, 80)
|
||||||
r.RenderHostmaps("Derp hostmaps", myControl, theirControl)
|
r.RenderHostmaps("Derp hostmaps", myControl, theirControl)
|
||||||
@@ -551,7 +535,7 @@ func TestRelays(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger a handshake from me to them via the relay")
|
t.Log("Trigger a handshake from me to them via the relay")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
@@ -581,7 +565,7 @@ func TestRelaysDontCareAboutIps(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger a handshake from me to them via the relay")
|
t.Log("Trigger a handshake from me to them via the relay")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
@@ -611,14 +595,14 @@ func TestReestablishRelays(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger a handshake from me to them via the relay")
|
t.Log("Trigger a handshake from me to them via the relay")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
assertUdpPacket(t, []byte("Hi from me"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi from me"), p, myVpnIpNet[0].Addr(), theirVpnIpNet[0].Addr(), 80, 80)
|
||||||
|
|
||||||
t.Log("Ensure packet traversal from them to me via the relay")
|
t.Log("Ensure packet traversal from them to me via the relay")
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them"))
|
||||||
|
|
||||||
p = r.RouteForAllUntilTxTun(myControl)
|
p = r.RouteForAllUntilTxTun(myControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
@@ -633,7 +617,7 @@ func TestReestablishRelays(t *testing.T) {
|
|||||||
for curIndexes >= start {
|
for curIndexes >= start {
|
||||||
curIndexes = len(myControl.GetHostmap().Indexes)
|
curIndexes = len(myControl.GetHostmap().Indexes)
|
||||||
r.Logf("Wait for the dead index to go away:start=%v indexes, current=%v indexes", start, curIndexes)
|
r.Logf("Wait for the dead index to go away:start=%v indexes, current=%v indexes", start, curIndexes)
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me should fail")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me should fail"))
|
||||||
|
|
||||||
r.RouteForAllExitFunc(func(p *udp.Packet, c *nebula.Control) router.ExitType {
|
r.RouteForAllExitFunc(func(p *udp.Packet, c *nebula.Control) router.ExitType {
|
||||||
return router.RouteAndExit
|
return router.RouteAndExit
|
||||||
@@ -650,7 +634,7 @@ func TestReestablishRelays(t *testing.T) {
|
|||||||
myControl.InjectLightHouseAddr(relayVpnIpNet[0].Addr(), relayUdpAddr)
|
myControl.InjectLightHouseAddr(relayVpnIpNet[0].Addr(), relayUdpAddr)
|
||||||
myControl.InjectRelays(theirVpnIpNet[0].Addr(), []netip.Addr{relayVpnIpNet[0].Addr()})
|
myControl.InjectRelays(theirVpnIpNet[0].Addr(), []netip.Addr{relayVpnIpNet[0].Addr()})
|
||||||
relayControl.InjectLightHouseAddr(theirVpnIpNet[0].Addr(), theirUdpAddr)
|
relayControl.InjectLightHouseAddr(theirVpnIpNet[0].Addr(), theirUdpAddr)
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p = r.RouteForAllUntilTxTun(theirControl)
|
p = r.RouteForAllUntilTxTun(theirControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
@@ -685,7 +669,7 @@ func TestReestablishRelays(t *testing.T) {
|
|||||||
t.Log("Assert the tunnel works the other way, too")
|
t.Log("Assert the tunnel works the other way, too")
|
||||||
for {
|
for {
|
||||||
t.Log("RouteForAllUntilTxTun")
|
t.Log("RouteForAllUntilTxTun")
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them"))
|
||||||
|
|
||||||
p = r.RouteForAllUntilTxTun(myControl)
|
p = r.RouteForAllUntilTxTun(myControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
@@ -755,8 +739,8 @@ func TestStage1RaceRelays(t *testing.T) {
|
|||||||
assertTunnel(t, theirVpnIpNet[0].Addr(), relayVpnIpNet[0].Addr(), theirControl, relayControl, r)
|
assertTunnel(t, theirVpnIpNet[0].Addr(), relayVpnIpNet[0].Addr(), theirControl, relayControl, r)
|
||||||
|
|
||||||
r.Log("Trigger a handshake from both them and me via relay to them and me")
|
r.Log("Trigger a handshake from both them and me via relay to them and me")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them"))
|
||||||
|
|
||||||
r.Log("Wait for a packet from them to me")
|
r.Log("Wait for a packet from them to me")
|
||||||
p := r.RouteForAllUntilTxTun(myControl)
|
p := r.RouteForAllUntilTxTun(myControl)
|
||||||
@@ -803,8 +787,8 @@ func TestStage1RaceRelays2(t *testing.T) {
|
|||||||
assertTunnel(t, theirVpnIpNet[0].Addr(), relayVpnIpNet[0].Addr(), theirControl, relayControl, r)
|
assertTunnel(t, theirVpnIpNet[0].Addr(), relayVpnIpNet[0].Addr(), theirControl, relayControl, r)
|
||||||
|
|
||||||
r.Log("Trigger a handshake from both them and me via relay to them and me")
|
r.Log("Trigger a handshake from both them and me via relay to them and me")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them"))
|
||||||
|
|
||||||
//r.RouteUntilAfterMsgType(myControl, header.Control, header.MessageNone)
|
//r.RouteUntilAfterMsgType(myControl, header.Control, header.MessageNone)
|
||||||
//r.RouteUntilAfterMsgType(theirControl, header.Control, header.MessageNone)
|
//r.RouteUntilAfterMsgType(theirControl, header.Control, header.MessageNone)
|
||||||
@@ -868,7 +852,7 @@ func TestRehandshakingRelays(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger a handshake from me to them via the relay")
|
t.Log("Trigger a handshake from me to them via the relay")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
@@ -973,7 +957,7 @@ func TestRehandshakingRelaysPrimary(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger a handshake from me to them via the relay")
|
t.Log("Trigger a handshake from me to them via the relay")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
@@ -1275,8 +1259,8 @@ func TestRaceRegression(t *testing.T) {
|
|||||||
//them rx stage:2 initiatorIndex=120607833 responderIndex=4209862089
|
//them rx stage:2 initiatorIndex=120607833 responderIndex=4209862089
|
||||||
|
|
||||||
t.Log("Start both handshakes")
|
t.Log("Start both handshakes")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnIpNet[0].Addr(), 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, theirVpnIpNet[0].Addr(), 80, []byte("Hi from them"))
|
||||||
|
|
||||||
t.Log("Get both stage 1")
|
t.Log("Get both stage 1")
|
||||||
myStage1ForThem := myControl.GetFromUDP(true)
|
myStage1ForThem := myControl.GetFromUDP(true)
|
||||||
@@ -1492,7 +1476,7 @@ func TestGoodHandshakeUnsafeDest(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Send a udp packet through to begin standing up the tunnel, this should come out the other side")
|
t.Log("Send a udp packet through to begin standing up the tunnel, this should come out the other side")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(spookyDest, 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(spookyDest, 80, myVpnIpNet[0].Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
t.Log("Have them consume my stage 0 packet. They have a tunnel now")
|
t.Log("Have them consume my stage 0 packet. They have a tunnel now")
|
||||||
theirControl.InjectUDPPacket(myControl.GetFromUDP(true))
|
theirControl.InjectUDPPacket(myControl.GetFromUDP(true))
|
||||||
@@ -1520,7 +1504,7 @@ func TestGoodHandshakeUnsafeDest(t *testing.T) {
|
|||||||
assertUdpPacket(t, []byte("Hi from me"), myCachedPacket, myVpnIpNet[0].Addr(), spookyDest, 80, 80)
|
assertUdpPacket(t, []byte("Hi from me"), myCachedPacket, myVpnIpNet[0].Addr(), spookyDest, 80, 80)
|
||||||
|
|
||||||
//reply
|
//reply
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnIpNet[0].Addr(), 80, spookyDest, 80, []byte("Hi from the spookyman")))
|
theirControl.InjectTunUDPPacket(myVpnIpNet[0].Addr(), 80, spookyDest, 80, []byte("Hi from the spookyman"))
|
||||||
//wait for reply
|
//wait for reply
|
||||||
theirControl.WaitForType(1, 0, myControl)
|
theirControl.WaitForType(1, 0, myControl)
|
||||||
theirCachedPacket := myControl.GetFromTun(true)
|
theirCachedPacket := myControl.GetFromTun(true)
|
||||||
|
|||||||
+6
-59
@@ -4,13 +4,15 @@
|
|||||||
package e2e
|
package e2e
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"log/slog"
|
"io"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"log/slog"
|
||||||
|
|
||||||
"dario.cat/mergo"
|
"dario.cat/mergo"
|
||||||
"github.com/google/gopacket"
|
"github.com/google/gopacket"
|
||||||
"github.com/google/gopacket/layers"
|
"github.com/google/gopacket/layers"
|
||||||
@@ -292,12 +294,12 @@ func deadline(t *testing.T, seconds time.Duration) doneCb {
|
|||||||
|
|
||||||
func assertTunnel(t testing.TB, vpnIpA, vpnIpB netip.Addr, controlA, controlB *nebula.Control, r *router.R) {
|
func assertTunnel(t testing.TB, vpnIpA, vpnIpB netip.Addr, controlA, controlB *nebula.Control, r *router.R) {
|
||||||
// Send a packet from them to me
|
// Send a packet from them to me
|
||||||
controlB.InjectTunPacket(BuildTunUDPPacket(vpnIpA, 80, vpnIpB, 90, []byte("Hi from B")))
|
controlB.InjectTunUDPPacket(vpnIpA, 80, vpnIpB, 90, []byte("Hi from B"))
|
||||||
bPacket := r.RouteForAllUntilTxTun(controlA)
|
bPacket := r.RouteForAllUntilTxTun(controlA)
|
||||||
assertUdpPacket(t, []byte("Hi from B"), bPacket, vpnIpB, vpnIpA, 90, 80)
|
assertUdpPacket(t, []byte("Hi from B"), bPacket, vpnIpB, vpnIpA, 90, 80)
|
||||||
|
|
||||||
// And once more from me to them
|
// And once more from me to them
|
||||||
controlA.InjectTunPacket(BuildTunUDPPacket(vpnIpB, 80, vpnIpA, 90, []byte("Hello from A")))
|
controlA.InjectTunUDPPacket(vpnIpB, 80, vpnIpA, 90, []byte("Hello from A"))
|
||||||
aPacket := r.RouteForAllUntilTxTun(controlB)
|
aPacket := r.RouteForAllUntilTxTun(controlB)
|
||||||
assertUdpPacket(t, []byte("Hello from A"), aPacket, vpnIpA, vpnIpB, 90, 80)
|
assertUdpPacket(t, []byte("Hello from A"), aPacket, vpnIpA, vpnIpB, 90, 80)
|
||||||
}
|
}
|
||||||
@@ -380,7 +382,7 @@ func getAddrs(ns []netip.Prefix) []netip.Addr {
|
|||||||
func NewTestLogger() *slog.Logger {
|
func NewTestLogger() *slog.Logger {
|
||||||
v := os.Getenv("TEST_LOGS")
|
v := os.Getenv("TEST_LOGS")
|
||||||
if v == "" {
|
if v == "" {
|
||||||
return slog.New(slog.DiscardHandler)
|
return slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
}
|
}
|
||||||
|
|
||||||
level := slog.LevelInfo
|
level := slog.LevelInfo
|
||||||
@@ -406,58 +408,3 @@ func testLogLevelName() string {
|
|||||||
}
|
}
|
||||||
return "info"
|
return "info"
|
||||||
}
|
}
|
||||||
|
|
||||||
// BuildTunUDPPacket assembles an IP+UDP packet suitable for Control.InjectTunPacket.
|
|
||||||
// Using UDP here because it's a simpler protocol.
|
|
||||||
func BuildTunUDPPacket(toAddr netip.Addr, toPort uint16, fromAddr netip.Addr, fromPort uint16, data []byte) []byte {
|
|
||||||
serialize := make([]gopacket.SerializableLayer, 0)
|
|
||||||
var netLayer gopacket.NetworkLayer
|
|
||||||
if toAddr.Is6() {
|
|
||||||
if !fromAddr.Is6() {
|
|
||||||
panic("Cant send ipv6 to ipv4")
|
|
||||||
}
|
|
||||||
ip := &layers.IPv6{
|
|
||||||
Version: 6,
|
|
||||||
NextHeader: layers.IPProtocolUDP,
|
|
||||||
SrcIP: fromAddr.Unmap().AsSlice(),
|
|
||||||
DstIP: toAddr.Unmap().AsSlice(),
|
|
||||||
}
|
|
||||||
serialize = append(serialize, ip)
|
|
||||||
netLayer = ip
|
|
||||||
} else {
|
|
||||||
if !fromAddr.Is4() {
|
|
||||||
panic("Cant send ipv4 to ipv6")
|
|
||||||
}
|
|
||||||
|
|
||||||
ip := &layers.IPv4{
|
|
||||||
Version: 4,
|
|
||||||
TTL: 64,
|
|
||||||
Protocol: layers.IPProtocolUDP,
|
|
||||||
SrcIP: fromAddr.Unmap().AsSlice(),
|
|
||||||
DstIP: toAddr.Unmap().AsSlice(),
|
|
||||||
}
|
|
||||||
serialize = append(serialize, ip)
|
|
||||||
netLayer = ip
|
|
||||||
}
|
|
||||||
|
|
||||||
udp := layers.UDP{
|
|
||||||
SrcPort: layers.UDPPort(fromPort),
|
|
||||||
DstPort: layers.UDPPort(toPort),
|
|
||||||
}
|
|
||||||
if err := udp.SetNetworkLayerForChecksum(netLayer); err != nil {
|
|
||||||
panic(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
buffer := gopacket.NewSerializeBuffer()
|
|
||||||
opt := gopacket.SerializeOptions{
|
|
||||||
ComputeChecksums: true,
|
|
||||||
FixLengths: true,
|
|
||||||
}
|
|
||||||
|
|
||||||
serialize = append(serialize, &udp, gopacket.Payload(data))
|
|
||||||
if err := gopacket.SerializeLayers(buffer, opt, serialize...); err != nil {
|
|
||||||
panic(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return buffer.Bytes()
|
|
||||||
}
|
|
||||||
|
|||||||
+7
-3
@@ -18,10 +18,14 @@ import (
|
|||||||
// retry mechanism gives the wg.Wait()-driven goroutines a moment to drain
|
// retry mechanism gives the wg.Wait()-driven goroutines a moment to drain
|
||||||
// before failing the assertion.
|
// before failing the assertion.
|
||||||
//
|
//
|
||||||
// Intentionally NOT t.Parallel()'d: concurrent tests would have their own
|
// IgnoreCurrent is necessary in the parallelized suite: other tests can
|
||||||
// goroutines running and trip the assertion.
|
// leave goroutines mid-shutdown when this one runs (Stop is async, the
|
||||||
|
// wg.Wait() drain is not blocking on test return). We're checking that
|
||||||
|
// *this* test's setup tears down cleanly, not that the whole suite is
|
||||||
|
// idle at this moment. Intentionally NOT t.Parallel()'d for the same
|
||||||
|
// reason — concurrent test goroutines would always show up.
|
||||||
func TestNoGoroutineLeaks(t *testing.T) {
|
func TestNoGoroutineLeaks(t *testing.T) {
|
||||||
defer goleak.VerifyNone(t)
|
defer goleak.VerifyNone(t, goleak.IgnoreCurrent())
|
||||||
|
|
||||||
ca, _, caKey, _ := cert_test.NewTestCaCert(cert.Version1, cert.Curve_CURVE25519, time.Now(), time.Now().Add(10*time.Minute), nil, nil, []string{})
|
ca, _, caKey, _ := cert_test.NewTestCaCert(cert.Version1, cert.Curve_CURVE25519, time.Now(), time.Now().Add(10*time.Minute), nil, nil, []string{})
|
||||||
myControl, myVpnIpNet, myUdpAddr, _ := newSimpleServer(cert.Version1, ca, caKey, "me", "10.128.0.1/24", nil)
|
myControl, myVpnIpNet, myUdpAddr, _ := newSimpleServer(cert.Version1, ca, caKey, "me", "10.128.0.1/24", nil)
|
||||||
|
|||||||
+54
-188
@@ -13,7 +13,6 @@ import (
|
|||||||
"regexp"
|
"regexp"
|
||||||
"sort"
|
"sort"
|
||||||
"sync"
|
"sync"
|
||||||
"sync/atomic"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -25,19 +24,6 @@ import (
|
|||||||
"golang.org/x/exp/maps"
|
"golang.org/x/exp/maps"
|
||||||
)
|
)
|
||||||
|
|
||||||
// outNatKey is the (from, to) pair used by outNat. Comparable struct, so it works as a map key without the
|
|
||||||
// allocation cost of a string-concat key.
|
|
||||||
type outNatKey struct {
|
|
||||||
from, to netip.AddrPort
|
|
||||||
}
|
|
||||||
|
|
||||||
// fannedPacket pairs a UDP TX packet with its source control so the router can route it after popping from
|
|
||||||
// the fan-in channel.
|
|
||||||
type fannedPacket struct {
|
|
||||||
from *nebula.Control
|
|
||||||
pkt *udp.Packet
|
|
||||||
}
|
|
||||||
|
|
||||||
type R struct {
|
type R struct {
|
||||||
// Simple map of the ip:port registered on a control to the control
|
// Simple map of the ip:port registered on a control to the control
|
||||||
// Basically a router, right?
|
// Basically a router, right?
|
||||||
@@ -48,28 +34,12 @@ type R struct {
|
|||||||
|
|
||||||
// A last used map, if an inbound packet hit the inNat map then
|
// A last used map, if an inbound packet hit the inNat map then
|
||||||
// all return packets should use the same last used inbound address for the outbound sender
|
// all return packets should use the same last used inbound address for the outbound sender
|
||||||
outNat map[outNatKey]netip.AddrPort
|
// map[from address + ":" + to address] => ip:port to rewrite in the udp packet to receiver
|
||||||
|
outNat map[string]netip.AddrPort
|
||||||
|
|
||||||
// A map of vpn ip to the nebula control it belongs to
|
// A map of vpn ip to the nebula control it belongs to
|
||||||
vpnControls map[netip.Addr]*nebula.Control
|
vpnControls map[netip.Addr]*nebula.Control
|
||||||
|
|
||||||
// Cached select infrastructure for RouteForAllUntilTxTun.
|
|
||||||
// The controls map is immutable after NewR so the cases are good for the test lifetime.
|
|
||||||
// We only rebuild if a different receiver is asked.
|
|
||||||
selRecvCtl *nebula.Control
|
|
||||||
selCases []reflect.SelectCase
|
|
||||||
selCtls []*nebula.Control
|
|
||||||
|
|
||||||
// Optional fan-in mode for hot-path benchmarks: one forwarder goroutine per control drains UDP TX into udpFanIn,
|
|
||||||
// so RouteForAllUntilTxTun can do a fixed 2-way native select instead of paying reflect.Select per call.
|
|
||||||
// Off by default (would otherwise interleave with tests that use GetFromUDP directly on the same control).
|
|
||||||
// Enabled by EnableFanIn.
|
|
||||||
udpFanIn chan fannedPacket
|
|
||||||
stopFanIn chan struct{}
|
|
||||||
fanInWG sync.WaitGroup
|
|
||||||
fanInMu sync.Mutex
|
|
||||||
fanInOn atomic.Bool
|
|
||||||
|
|
||||||
ignoreFlows []ignoreFlow
|
ignoreFlows []ignoreFlow
|
||||||
flow []flowEntry
|
flow []flowEntry
|
||||||
|
|
||||||
@@ -149,7 +119,7 @@ func NewR(t testing.TB, controls ...*nebula.Control) *R {
|
|||||||
controls: make(map[netip.AddrPort]*nebula.Control),
|
controls: make(map[netip.AddrPort]*nebula.Control),
|
||||||
vpnControls: make(map[netip.Addr]*nebula.Control),
|
vpnControls: make(map[netip.Addr]*nebula.Control),
|
||||||
inNat: make(map[netip.AddrPort]*nebula.Control),
|
inNat: make(map[netip.AddrPort]*nebula.Control),
|
||||||
outNat: make(map[outNatKey]netip.AddrPort),
|
outNat: make(map[string]netip.AddrPort),
|
||||||
flow: []flowEntry{},
|
flow: []flowEntry{},
|
||||||
ignoreFlows: []ignoreFlow{},
|
ignoreFlows: []ignoreFlow{},
|
||||||
fn: filepath.Join("mermaid", fmt.Sprintf("%s.md", t.Name())),
|
fn: filepath.Join("mermaid", fmt.Sprintf("%s.md", t.Name())),
|
||||||
@@ -183,10 +153,8 @@ func NewR(t testing.TB, controls ...*nebula.Control) *R {
|
|||||||
case <-ctx.Done():
|
case <-ctx.Done():
|
||||||
return
|
return
|
||||||
case <-clockSource.C:
|
case <-clockSource.C:
|
||||||
r.Lock()
|
|
||||||
r.renderHostmaps("clock tick")
|
r.renderHostmaps("clock tick")
|
||||||
r.renderFlow()
|
r.renderFlow()
|
||||||
r.Unlock()
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}()
|
}()
|
||||||
@@ -212,21 +180,15 @@ func (r *R) AddRoute(ip netip.Addr, port uint16, c *nebula.Control) {
|
|||||||
// RenderFlow renders the packet flow seen up until now and stops further automatic renders from happening.
|
// RenderFlow renders the packet flow seen up until now and stops further automatic renders from happening.
|
||||||
func (r *R) RenderFlow() {
|
func (r *R) RenderFlow() {
|
||||||
r.cancelRender()
|
r.cancelRender()
|
||||||
r.Lock()
|
|
||||||
defer r.Unlock()
|
|
||||||
r.renderFlow()
|
r.renderFlow()
|
||||||
}
|
}
|
||||||
|
|
||||||
// CancelFlowLogs stops flow logs from being tracked and destroys any logs already collected
|
// CancelFlowLogs stops flow logs from being tracked and destroys any logs already collected
|
||||||
func (r *R) CancelFlowLogs() {
|
func (r *R) CancelFlowLogs() {
|
||||||
r.cancelRender()
|
r.cancelRender()
|
||||||
r.Lock()
|
|
||||||
r.flow = nil
|
r.flow = nil
|
||||||
r.Unlock()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// renderFlow writes the flow log to disk. Caller must hold r.Lock. renderFlow reads r.flow / r.additionalGraphs and
|
|
||||||
// the *packet pointers stashed inside, all of which are mutated under the same lock by routing paths.
|
|
||||||
func (r *R) renderFlow() {
|
func (r *R) renderFlow() {
|
||||||
if r.flow == nil {
|
if r.flow == nil {
|
||||||
return
|
return
|
||||||
@@ -472,157 +434,68 @@ func (r *R) RouteUntilTxTun(sender *nebula.Control, receiver *nebula.Control) []
|
|||||||
panic("No control for udp tx " + a.String())
|
panic("No control for udp tx " + a.String())
|
||||||
}
|
}
|
||||||
fp := r.unlockedInjectFlow(sender, c, p, false)
|
fp := r.unlockedInjectFlow(sender, c, p, false)
|
||||||
c.InjectUDPPacket(p) // copies internally; original is ours to release
|
c.InjectUDPPacket(p)
|
||||||
fp.WasReceived()
|
fp.WasReceived()
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// RouteForAllUntilTxTun will route for everyone and return when a packet is seen on the receiver's tun.
|
// RouteForAllUntilTxTun will route for everyone and return when a packet is seen on receivers tun
|
||||||
// If a control's UDP TX address can't be matched to a registered control, we panic.
|
// If the router doesn't have the nebula controller for that address, we panic
|
||||||
//
|
|
||||||
// For allocation-sensitive callers (hot-path benchmarks, in particular relay
|
|
||||||
// benches with 3+ controls), call EnableFanIn() first.
|
|
||||||
func (r *R) RouteForAllUntilTxTun(receiver *nebula.Control) []byte {
|
func (r *R) RouteForAllUntilTxTun(receiver *nebula.Control) []byte {
|
||||||
if r.fanInOn.Load() {
|
|
||||||
return r.routeFanIn(receiver)
|
|
||||||
}
|
|
||||||
return r.routeReflect(receiver)
|
|
||||||
}
|
|
||||||
|
|
||||||
// routeFanIn is the alloc-free path used when EnableFanIn is in effect.
|
|
||||||
func (r *R) routeFanIn(receiver *nebula.Control) []byte {
|
|
||||||
tunTx := receiver.GetTunTxChan()
|
|
||||||
for {
|
|
||||||
select {
|
|
||||||
case p := <-tunTx:
|
|
||||||
r.Lock()
|
|
||||||
if r.flow != nil {
|
|
||||||
np := udp.Packet{Data: make([]byte, len(p))}
|
|
||||||
copy(np.Data, p)
|
|
||||||
r.unlockedInjectFlow(receiver, receiver, &np, true)
|
|
||||||
}
|
|
||||||
r.Unlock()
|
|
||||||
return p
|
|
||||||
case fp := <-r.udpFanIn:
|
|
||||||
r.routeUDP(fp.from, fp.pkt)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// routeReflect is the default reflect.Select-based path. Pays the boxing allocation per call but doesn't interfere
|
|
||||||
// with tests that pull packets directly from controls' UDP TX channels via GetFromUDP.
|
|
||||||
func (r *R) routeReflect(receiver *nebula.Control) []byte {
|
|
||||||
sc, cm := r.selectCasesFor(receiver)
|
|
||||||
for {
|
|
||||||
x, rx, _ := reflect.Select(sc)
|
|
||||||
if x == 0 {
|
|
||||||
p := rx.Interface().([]byte)
|
|
||||||
r.Lock()
|
|
||||||
if r.flow != nil {
|
|
||||||
np := udp.Packet{Data: make([]byte, len(p))}
|
|
||||||
copy(np.Data, p)
|
|
||||||
r.unlockedInjectFlow(cm[x], cm[x], &np, true)
|
|
||||||
}
|
|
||||||
r.Unlock()
|
|
||||||
return p
|
|
||||||
}
|
|
||||||
r.routeUDP(cm[x], rx.Interface().(*udp.Packet))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// EnableFanIn switches RouteForAllUntilTxTun to the alloc-free fan-in path.
|
|
||||||
// One forwarder goroutine per registered control drains UDP TX into a shared channel that RouteForAllUntilTxTun selects
|
|
||||||
// on alongside the receiver's TUN TX channel.
|
|
||||||
func (r *R) EnableFanIn() {
|
|
||||||
r.fanInMu.Lock()
|
|
||||||
defer r.fanInMu.Unlock()
|
|
||||||
if r.fanInOn.Load() {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
r.udpFanIn = make(chan fannedPacket, 32)
|
|
||||||
r.stopFanIn = make(chan struct{})
|
|
||||||
for _, c := range r.controls {
|
|
||||||
r.startFanInWorker(c)
|
|
||||||
}
|
|
||||||
r.fanInOn.Store(true)
|
|
||||||
r.t.Cleanup(r.stopFanInWorkers)
|
|
||||||
}
|
|
||||||
|
|
||||||
// startFanInWorker spawns a goroutine that drains c's UDP TX into r.udpFanIn.
|
|
||||||
func (r *R) startFanInWorker(c *nebula.Control) {
|
|
||||||
r.fanInWG.Add(1)
|
|
||||||
udpTx := c.GetUDPTxChan()
|
|
||||||
go func() {
|
|
||||||
defer r.fanInWG.Done()
|
|
||||||
for {
|
|
||||||
select {
|
|
||||||
case <-r.stopFanIn:
|
|
||||||
return
|
|
||||||
case p := <-udpTx:
|
|
||||||
select {
|
|
||||||
case <-r.stopFanIn:
|
|
||||||
p.Release()
|
|
||||||
return
|
|
||||||
case r.udpFanIn <- fannedPacket{from: c, pkt: p}:
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
}
|
|
||||||
|
|
||||||
// stopFanInWorkers signals the fan-in goroutines to exit and waits for them.
|
|
||||||
func (r *R) stopFanInWorkers() {
|
|
||||||
r.fanInMu.Lock()
|
|
||||||
wasOn := r.fanInOn.Swap(false)
|
|
||||||
r.fanInMu.Unlock()
|
|
||||||
if !wasOn {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
close(r.stopFanIn)
|
|
||||||
r.fanInWG.Wait()
|
|
||||||
}
|
|
||||||
|
|
||||||
// routeUDP forwards a UDP TX packet from the named source control to the destination control derived from p.To,
|
|
||||||
// releasing the source packet after InjectUDPPacket has copied its bytes into a fresh pool slot.
|
|
||||||
func (r *R) routeUDP(from *nebula.Control, p *udp.Packet) {
|
|
||||||
r.Lock()
|
|
||||||
defer r.Unlock()
|
|
||||||
a := from.GetUDPAddr()
|
|
||||||
c := r.getControl(a, p.To, p)
|
|
||||||
if c == nil {
|
|
||||||
panic(fmt.Sprintf("No control for udp tx %s", p.To))
|
|
||||||
}
|
|
||||||
fp := r.unlockedInjectFlow(from, c, p, false)
|
|
||||||
c.InjectUDPPacket(p) // copies internally; original is ours to release
|
|
||||||
fp.WasReceived()
|
|
||||||
p.Release()
|
|
||||||
}
|
|
||||||
|
|
||||||
// selectCasesFor returns the SelectCase array used by routeReflect: one slot for the receiver's TUN TX channel followed
|
|
||||||
// by one per control's UDP TX channel. Cached for the test lifetime, only rebuilt if the receiver changes.
|
|
||||||
func (r *R) selectCasesFor(receiver *nebula.Control) ([]reflect.SelectCase, []*nebula.Control) {
|
|
||||||
r.Lock()
|
|
||||||
defer r.Unlock()
|
|
||||||
if r.selRecvCtl == receiver && r.selCases != nil {
|
|
||||||
return r.selCases, r.selCtls
|
|
||||||
}
|
|
||||||
sc := make([]reflect.SelectCase, len(r.controls)+1)
|
sc := make([]reflect.SelectCase, len(r.controls)+1)
|
||||||
cm := make([]*nebula.Control, len(r.controls)+1)
|
cm := make([]*nebula.Control, len(r.controls)+1)
|
||||||
sc[0] = reflect.SelectCase{Dir: reflect.SelectRecv, Chan: reflect.ValueOf(receiver.GetTunTxChan())}
|
|
||||||
cm[0] = receiver
|
i := 0
|
||||||
i := 1
|
sc[i] = reflect.SelectCase{
|
||||||
|
Dir: reflect.SelectRecv,
|
||||||
|
Chan: reflect.ValueOf(receiver.GetTunTxChan()),
|
||||||
|
Send: reflect.Value{},
|
||||||
|
}
|
||||||
|
cm[i] = receiver
|
||||||
|
|
||||||
|
i++
|
||||||
for _, c := range r.controls {
|
for _, c := range r.controls {
|
||||||
sc[i] = reflect.SelectCase{Dir: reflect.SelectRecv, Chan: reflect.ValueOf(c.GetUDPTxChan())}
|
sc[i] = reflect.SelectCase{
|
||||||
|
Dir: reflect.SelectRecv,
|
||||||
|
Chan: reflect.ValueOf(c.GetUDPTxChan()),
|
||||||
|
Send: reflect.Value{},
|
||||||
|
}
|
||||||
|
|
||||||
cm[i] = c
|
cm[i] = c
|
||||||
i++
|
i++
|
||||||
}
|
}
|
||||||
r.selRecvCtl = receiver
|
|
||||||
r.selCases = sc
|
for {
|
||||||
r.selCtls = cm
|
x, rx, _ := reflect.Select(sc)
|
||||||
return sc, cm
|
r.Lock()
|
||||||
|
|
||||||
|
if x == 0 {
|
||||||
|
// we are the tun tx, we can exit
|
||||||
|
p := rx.Interface().([]byte)
|
||||||
|
np := udp.Packet{Data: make([]byte, len(p))}
|
||||||
|
copy(np.Data, p)
|
||||||
|
|
||||||
|
r.unlockedInjectFlow(cm[x], cm[x], &np, true)
|
||||||
|
r.Unlock()
|
||||||
|
return p
|
||||||
|
|
||||||
|
} else {
|
||||||
|
// we are a udp tx, route and continue
|
||||||
|
p := rx.Interface().(*udp.Packet)
|
||||||
|
a := cm[x].GetUDPAddr()
|
||||||
|
c := r.getControl(a, p.To, p)
|
||||||
|
if c == nil {
|
||||||
|
r.Unlock()
|
||||||
|
panic(fmt.Sprintf("No control for udp tx %s", p.To))
|
||||||
|
}
|
||||||
|
fp := r.unlockedInjectFlow(cm[x], c, p, false)
|
||||||
|
c.InjectUDPPacket(p)
|
||||||
|
fp.WasReceived()
|
||||||
|
}
|
||||||
|
r.Unlock()
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// RouteExitFunc will call the whatDo func with each udp packet from sender.
|
// RouteExitFunc will call the whatDo func with each udp packet from sender.
|
||||||
@@ -649,7 +522,6 @@ func (r *R) RouteExitFunc(sender *nebula.Control, whatDo ExitFunc) {
|
|||||||
switch e {
|
switch e {
|
||||||
case ExitNow:
|
case ExitNow:
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
return
|
return
|
||||||
|
|
||||||
case RouteAndExit:
|
case RouteAndExit:
|
||||||
@@ -657,7 +529,6 @@ func (r *R) RouteExitFunc(sender *nebula.Control, whatDo ExitFunc) {
|
|||||||
receiver.InjectUDPPacket(p)
|
receiver.InjectUDPPacket(p)
|
||||||
fp.WasReceived()
|
fp.WasReceived()
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
return
|
return
|
||||||
|
|
||||||
case KeepRouting:
|
case KeepRouting:
|
||||||
@@ -670,7 +541,6 @@ func (r *R) RouteExitFunc(sender *nebula.Control, whatDo ExitFunc) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -771,7 +641,6 @@ func (r *R) RouteForAllExitFunc(whatDo ExitFunc) {
|
|||||||
switch e {
|
switch e {
|
||||||
case ExitNow:
|
case ExitNow:
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
return
|
return
|
||||||
|
|
||||||
case RouteAndExit:
|
case RouteAndExit:
|
||||||
@@ -779,7 +648,6 @@ func (r *R) RouteForAllExitFunc(whatDo ExitFunc) {
|
|||||||
receiver.InjectUDPPacket(p)
|
receiver.InjectUDPPacket(p)
|
||||||
fp.WasReceived()
|
fp.WasReceived()
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
return
|
return
|
||||||
|
|
||||||
case KeepRouting:
|
case KeepRouting:
|
||||||
@@ -791,7 +659,6 @@ func (r *R) RouteForAllExitFunc(whatDo ExitFunc) {
|
|||||||
panic(fmt.Sprintf("Unknown exitFunc return: %v", e))
|
panic(fmt.Sprintf("Unknown exitFunc return: %v", e))
|
||||||
}
|
}
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -835,20 +702,19 @@ func (r *R) FlushAll() {
|
|||||||
}
|
}
|
||||||
receiver.InjectUDPPacket(p)
|
receiver.InjectUDPPacket(p)
|
||||||
r.Unlock()
|
r.Unlock()
|
||||||
p.Release()
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// getControl performs or seeds NAT translation and returns the control for toAddr, p from fields may change
|
// getControl performs or seeds NAT translation and returns the control for toAddr, p from fields may change
|
||||||
// This is an internal router function, the caller must hold the lock
|
// This is an internal router function, the caller must hold the lock
|
||||||
func (r *R) getControl(fromAddr, toAddr netip.AddrPort, p *udp.Packet) *nebula.Control {
|
func (r *R) getControl(fromAddr, toAddr netip.AddrPort, p *udp.Packet) *nebula.Control {
|
||||||
if newAddr, ok := r.outNat[outNatKey{from: fromAddr, to: toAddr}]; ok {
|
if newAddr, ok := r.outNat[fromAddr.String()+":"+toAddr.String()]; ok {
|
||||||
p.From = newAddr
|
p.From = newAddr
|
||||||
}
|
}
|
||||||
|
|
||||||
c, ok := r.inNat[toAddr]
|
c, ok := r.inNat[toAddr]
|
||||||
if ok {
|
if ok {
|
||||||
r.outNat[outNatKey{from: c.GetUDPAddr(), to: fromAddr}] = toAddr
|
r.outNat[c.GetUDPAddr().String()+":"+fromAddr.String()] = toAddr
|
||||||
return c
|
return c
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,125 +0,0 @@
|
|||||||
//go:build e2e_testing
|
|
||||||
// +build e2e_testing
|
|
||||||
|
|
||||||
package e2e
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/ed25519"
|
|
||||||
"crypto/rand"
|
|
||||||
"encoding/pem"
|
|
||||||
"net"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/cert"
|
|
||||||
"github.com/slackhq/nebula/cert_test"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"golang.org/x/crypto/ssh"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestSSHDLifecycle(t *testing.T) {
|
|
||||||
// TestSSHDLifecycle exercises the in-process sshd through several config reloads and a Control.Stop.
|
|
||||||
ca, _, caKey, _ := cert_test.NewTestCaCert(
|
|
||||||
cert.Version1, cert.Curve_CURVE25519,
|
|
||||||
time.Now(), time.Now().Add(10*time.Minute),
|
|
||||||
nil, nil, []string{},
|
|
||||||
)
|
|
||||||
|
|
||||||
hostKeyPEM := generateSSHHostKey(t)
|
|
||||||
clientSigner, clientAuthKey := generateSSHClientKey(t)
|
|
||||||
sshdAddr := allocLoopbackPort(t)
|
|
||||||
|
|
||||||
overrides := m{
|
|
||||||
"sshd": m{
|
|
||||||
"enabled": true,
|
|
||||||
"listen": sshdAddr,
|
|
||||||
"host_key": hostKeyPEM,
|
|
||||||
"authorized_users": []m{{
|
|
||||||
"user": "tester",
|
|
||||||
"keys": []string{clientAuthKey},
|
|
||||||
}},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
control, _, _, _ := newSimpleServer(cert.Version1, ca, caKey, "sshd-test", "10.222.0.1/24", overrides)
|
|
||||||
control.Start()
|
|
||||||
t.Cleanup(func() { control.Stop() })
|
|
||||||
|
|
||||||
// sshd binds in a goroutine after Start returns; wait for it.
|
|
||||||
require.Eventually(t, func() bool { return canDial(sshdAddr) }, 2*time.Second, 25*time.Millisecond,
|
|
||||||
"sshd never started listening")
|
|
||||||
|
|
||||||
for i := 1; i <= 3; i++ {
|
|
||||||
out := sshExecReload(t, sshdAddr, clientSigner)
|
|
||||||
assert.Contains(t, out, "Reloading config", "reload cycle %d", i)
|
|
||||||
require.Eventually(t, func() bool { return canDial(sshdAddr) }, 2*time.Second, 25*time.Millisecond,
|
|
||||||
"sshd not listening after reload cycle %d", i)
|
|
||||||
}
|
|
||||||
|
|
||||||
control.Stop()
|
|
||||||
require.Eventually(t, func() bool { return !canDial(sshdAddr) }, 2*time.Second, 25*time.Millisecond,
|
|
||||||
"sshd still listening after Control.Stop")
|
|
||||||
}
|
|
||||||
|
|
||||||
func canDial(addr string) bool {
|
|
||||||
c, err := net.DialTimeout("tcp", addr, 100*time.Millisecond)
|
|
||||||
if err != nil {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
_ = c.Close()
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
// allocLoopbackPort grabs an unused TCP port on 127.0.0.1, closes it, and returns the address. There
|
|
||||||
// is a small race between releasing the port and the sshd reclaiming it; in practice the OS keeps the
|
|
||||||
// port available long enough for the test to bind it.
|
|
||||||
func allocLoopbackPort(t *testing.T) string {
|
|
||||||
t.Helper()
|
|
||||||
l, err := net.Listen("tcp", "127.0.0.1:0")
|
|
||||||
require.NoError(t, err)
|
|
||||||
addr := l.Addr().String()
|
|
||||||
require.NoError(t, l.Close())
|
|
||||||
return addr
|
|
||||||
}
|
|
||||||
|
|
||||||
func generateSSHHostKey(t *testing.T) string {
|
|
||||||
t.Helper()
|
|
||||||
_, priv, err := ed25519.GenerateKey(rand.Reader)
|
|
||||||
require.NoError(t, err)
|
|
||||||
block, err := ssh.MarshalPrivateKey(priv, "nebula-e2e-host")
|
|
||||||
require.NoError(t, err)
|
|
||||||
return string(pem.EncodeToMemory(block))
|
|
||||||
}
|
|
||||||
|
|
||||||
func generateSSHClientKey(t *testing.T) (ssh.Signer, string) {
|
|
||||||
t.Helper()
|
|
||||||
_, priv, err := ed25519.GenerateKey(rand.Reader)
|
|
||||||
require.NoError(t, err)
|
|
||||||
signer, err := ssh.NewSignerFromKey(priv)
|
|
||||||
require.NoError(t, err)
|
|
||||||
auth := strings.TrimSpace(string(ssh.MarshalAuthorizedKey(signer.PublicKey())))
|
|
||||||
return signer, auth
|
|
||||||
}
|
|
||||||
|
|
||||||
func sshExecReload(t *testing.T, addr string, signer ssh.Signer) string {
|
|
||||||
t.Helper()
|
|
||||||
cfg := &ssh.ClientConfig{
|
|
||||||
User: "tester",
|
|
||||||
Auth: []ssh.AuthMethod{ssh.PublicKeys(signer)},
|
|
||||||
HostKeyCallback: ssh.InsecureIgnoreHostKey(),
|
|
||||||
Timeout: 2 * time.Second,
|
|
||||||
}
|
|
||||||
client, err := ssh.Dial("tcp", addr, cfg)
|
|
||||||
require.NoError(t, err)
|
|
||||||
defer client.Close()
|
|
||||||
|
|
||||||
sess, err := client.NewSession()
|
|
||||||
require.NoError(t, err)
|
|
||||||
defer sess.Close()
|
|
||||||
|
|
||||||
// reload tears the channel down before sending exit-status, so Output returns an error on the
|
|
||||||
// channel close. The output buffer still has whatever the reload callback wrote before that.
|
|
||||||
out, _ := sess.Output("reload")
|
|
||||||
return string(out)
|
|
||||||
}
|
|
||||||
+2
-2
@@ -355,14 +355,14 @@ func TestCrossStackRelaysWork(t *testing.T) {
|
|||||||
theirControl.Start()
|
theirControl.Start()
|
||||||
|
|
||||||
t.Log("Trigger a handshake from me to them via the relay")
|
t.Log("Trigger a handshake from me to them via the relay")
|
||||||
myControl.InjectTunPacket(BuildTunUDPPacket(theirVpnV6.Addr(), 80, myVpnV6.Addr(), 80, []byte("Hi from me")))
|
myControl.InjectTunUDPPacket(theirVpnV6.Addr(), 80, myVpnV6.Addr(), 80, []byte("Hi from me"))
|
||||||
|
|
||||||
p := r.RouteForAllUntilTxTun(theirControl)
|
p := r.RouteForAllUntilTxTun(theirControl)
|
||||||
r.Log("Assert the tunnel works")
|
r.Log("Assert the tunnel works")
|
||||||
assertUdpPacket(t, []byte("Hi from me"), p, myVpnV6.Addr(), theirVpnV6.Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi from me"), p, myVpnV6.Addr(), theirVpnV6.Addr(), 80, 80)
|
||||||
|
|
||||||
t.Log("reply?")
|
t.Log("reply?")
|
||||||
theirControl.InjectTunPacket(BuildTunUDPPacket(myVpnV6.Addr(), 80, theirVpnV6.Addr(), 80, []byte("Hi from them")))
|
theirControl.InjectTunUDPPacket(myVpnV6.Addr(), 80, theirVpnV6.Addr(), 80, []byte("Hi from them"))
|
||||||
p = r.RouteForAllUntilTxTun(myControl)
|
p = r.RouteForAllUntilTxTun(myControl)
|
||||||
assertUdpPacket(t, []byte("Hi from them"), p, theirVpnV6.Addr(), myVpnV6.Addr(), 80, 80)
|
assertUdpPacket(t, []byte("Hi from them"), p, theirVpnV6.Addr(), myVpnV6.Addr(), 80, 80)
|
||||||
|
|
||||||
|
|||||||
@@ -1,124 +0,0 @@
|
|||||||
package nebula
|
|
||||||
|
|
||||||
import (
|
|
||||||
"log/slog"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestInnerECN(t *testing.T) {
|
|
||||||
cases := []struct {
|
|
||||||
name string
|
|
||||||
pkt []byte
|
|
||||||
want byte
|
|
||||||
}{
|
|
||||||
{"empty", nil, 0},
|
|
||||||
{"v4_NotECT", v4WithToS(0x00), 0x00},
|
|
||||||
{"v4_ECT0", v4WithToS(0x02), 0x02},
|
|
||||||
{"v4_ECT1", v4WithToS(0x01), 0x01},
|
|
||||||
{"v4_CE", v4WithToS(0x03), 0x03},
|
|
||||||
{"v4_DSCP_then_NotECT", v4WithToS(0x88 | 0x00), 0x00},
|
|
||||||
{"v4_DSCP_then_CE", v4WithToS(0x88 | 0x03), 0x03},
|
|
||||||
{"v6_NotECT", v6WithTC(0x00), 0x00},
|
|
||||||
{"v6_ECT0", v6WithTC(0x02), 0x02},
|
|
||||||
{"v6_CE", v6WithTC(0x03), 0x03},
|
|
||||||
{"v6_DSCP_then_CE", v6WithTC(0x88 | 0x03), 0x03},
|
|
||||||
{"unknown_version", []byte{0xa5, 0xff}, 0},
|
|
||||||
}
|
|
||||||
for _, c := range cases {
|
|
||||||
t.Run(c.name, func(t *testing.T) {
|
|
||||||
got := innerECN(c.pkt)
|
|
||||||
if got != c.want {
|
|
||||||
t.Errorf("innerECN=0x%02x want 0x%02x", got, c.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// v4WithToS returns a 2-byte slice tall enough for innerECN: byte 0 carries
|
|
||||||
// version=4 in the high nibble, byte 1 is the full ToS so we exercise both
|
|
||||||
// the DSCP and ECN portions through the byte 1 mask.
|
|
||||||
func v4WithToS(tos byte) []byte {
|
|
||||||
return []byte{0x45, tos}
|
|
||||||
}
|
|
||||||
|
|
||||||
// v6WithTC builds a 2-byte slice that places a known traffic class value
|
|
||||||
// across bytes 0 (high nibble of TC) and 1 (low nibble of TC). innerECN
|
|
||||||
// extracts ECN as (b[1]>>4)&0x03, which corresponds to TC[1:0].
|
|
||||||
func v6WithTC(tc byte) []byte {
|
|
||||||
return []byte{0x60 | (tc>>4)&0x0f, (tc & 0x0f) << 4}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestApplyOuterECN(t *testing.T) {
|
|
||||||
silent := slog.New(slog.DiscardHandler)
|
|
||||||
hi := &HostInfo{}
|
|
||||||
|
|
||||||
// Build a v4 packet helper with a given inner ECN field.
|
|
||||||
v4 := func(innerECN byte) []byte {
|
|
||||||
// 20-byte minimal IPv4 header with ToS = innerECN (DSCP zeroed).
|
|
||||||
return []byte{
|
|
||||||
0x45, innerECN, 0, 28,
|
|
||||||
0, 0, 0x40, 0,
|
|
||||||
64, 6, 0, 0,
|
|
||||||
10, 0, 0, 1,
|
|
||||||
10, 0, 0, 2,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
// Build a v6 packet helper with a given inner ECN field. ECN occupies
|
|
||||||
// TC[1:0] which sit at byte 1 mask 0x30.
|
|
||||||
v6 := func(innerECN byte) []byte {
|
|
||||||
// 40-byte minimal IPv6 header with TC[1:0] = innerECN.
|
|
||||||
pkt := make([]byte, 40)
|
|
||||||
pkt[0] = 0x60 // version=6, TC[7:4]=0
|
|
||||||
pkt[1] = (innerECN & 0x03) << 4 // TC[3:0]: low 2 bits = ECN, top 2 = DSCP-low (0)
|
|
||||||
return pkt
|
|
||||||
}
|
|
||||||
|
|
||||||
type cell struct {
|
|
||||||
outer byte
|
|
||||||
inner byte
|
|
||||||
wantECN byte
|
|
||||||
wantSame bool // expect inner unchanged (true => verify the byte didn't move)
|
|
||||||
}
|
|
||||||
|
|
||||||
// RFC 6040 normal-mode combine table. Only outer==CE causes mutation.
|
|
||||||
table := []cell{
|
|
||||||
{ecnNotECT, ecnNotECT, ecnNotECT, true},
|
|
||||||
{ecnNotECT, ecnECT0, ecnECT0, true},
|
|
||||||
{ecnNotECT, ecnECT1, ecnECT1, true},
|
|
||||||
{ecnNotECT, ecnCE, ecnCE, true},
|
|
||||||
|
|
||||||
{ecnECT0, ecnNotECT, ecnNotECT, true},
|
|
||||||
{ecnECT0, ecnECT0, ecnECT0, true},
|
|
||||||
{ecnECT0, ecnECT1, ecnECT1, true},
|
|
||||||
{ecnECT0, ecnCE, ecnCE, true},
|
|
||||||
|
|
||||||
{ecnECT1, ecnNotECT, ecnNotECT, true},
|
|
||||||
{ecnECT1, ecnECT0, ecnECT0, true},
|
|
||||||
{ecnECT1, ecnECT1, ecnECT1, true},
|
|
||||||
{ecnECT1, ecnCE, ecnCE, true},
|
|
||||||
|
|
||||||
{ecnCE, ecnNotECT, ecnNotECT, true}, // legacy: log, leave alone
|
|
||||||
{ecnCE, ecnECT0, ecnCE, false}, // CE folded in
|
|
||||||
{ecnCE, ecnECT1, ecnCE, false},
|
|
||||||
{ecnCE, ecnCE, ecnCE, true},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, c := range table {
|
|
||||||
t.Run("v4", func(t *testing.T) {
|
|
||||||
pkt := v4(c.inner)
|
|
||||||
applyOuterECN(pkt, c.outer, hi, silent)
|
|
||||||
got := pkt[1] & 0x03
|
|
||||||
if got != c.wantECN {
|
|
||||||
t.Errorf("v4 outer=0x%02x inner=0x%02x: got 0x%02x want 0x%02x", c.outer, c.inner, got, c.wantECN)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
t.Run("v6", func(t *testing.T) {
|
|
||||||
pkt := v6(c.inner)
|
|
||||||
applyOuterECN(pkt, c.outer, hi, silent)
|
|
||||||
got := (pkt[1] >> 4) & 0x03
|
|
||||||
if got != c.wantECN {
|
|
||||||
t.Errorf("v6 outer=0x%02x inner=0x%02x: got 0x%02x want 0x%02x", c.outer, c.inner, got, c.wantECN)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -138,14 +138,6 @@ listen:
|
|||||||
# max, net.core.rmem_max and net.core.wmem_max
|
# max, net.core.rmem_max and net.core.wmem_max
|
||||||
#read_buffer: 10485760
|
#read_buffer: 10485760
|
||||||
#write_buffer: 10485760
|
#write_buffer: 10485760
|
||||||
|
|
||||||
# On Windows only
|
|
||||||
# When true, Nebula installs a WFP (Windows Filtering Platform) PERMIT filter scoped to UDP at the listener port.
|
|
||||||
# WFP sits below Windows Defender Firewall, so this lets peer handshakes reach Nebula's outside socket regardless
|
|
||||||
# of WDF's inbound rules.
|
|
||||||
# Default true; set to false to leave WDF in charge of inbound decisions on the listener port. Not reloadable.
|
|
||||||
#windows_bypass_wdf: true
|
|
||||||
|
|
||||||
# By default, Nebula replies to packets it has no tunnel for with a "recv_error" packet. This packet helps speed up reconnection
|
# By default, Nebula replies to packets it has no tunnel for with a "recv_error" packet. This packet helps speed up reconnection
|
||||||
# in the case that Nebula on either side did not shut down cleanly. This response can be abused as a way to discover if Nebula is running
|
# in the case that Nebula on either side did not shut down cleanly. This response can be abused as a way to discover if Nebula is running
|
||||||
# on a host though. This option lets you configure if you want to send "recv_error" packets always, never, or only to private network remotes.
|
# on a host though. This option lets you configure if you want to send "recv_error" packets always, never, or only to private network remotes.
|
||||||
@@ -171,21 +163,17 @@ listen:
|
|||||||
|
|
||||||
punchy:
|
punchy:
|
||||||
# Continues to punch inbound/outbound at a regular interval to avoid expiration of firewall nat mappings
|
# Continues to punch inbound/outbound at a regular interval to avoid expiration of firewall nat mappings
|
||||||
# This setting is reloadable.
|
|
||||||
punch: true
|
punch: true
|
||||||
|
|
||||||
# respond means that a node you are trying to reach will connect back out to you if your hole punching fails
|
# respond means that a node you are trying to reach will connect back out to you if your hole punching fails
|
||||||
# this is extremely useful if one node is behind a difficult nat, such as a symmetric NAT
|
# this is extremely useful if one node is behind a difficult nat, such as a symmetric NAT
|
||||||
# Default is false
|
# Default is false
|
||||||
# This setting is reloadable.
|
|
||||||
#respond: true
|
#respond: true
|
||||||
|
|
||||||
# delays a punch response for misbehaving NATs, default is 1 second.
|
# delays a punch response for misbehaving NATs, default is 1 second.
|
||||||
# This setting is reloadable.
|
|
||||||
#delay: 1s
|
#delay: 1s
|
||||||
|
|
||||||
# set the delay before attempting punchy.respond. Default is 5 seconds. respond must be true to take effect.
|
# set the delay before attempting punchy.respond. Default is 5 seconds. respond must be true to take effect.
|
||||||
# This setting is reloadable.
|
|
||||||
#respond_delay: 5s
|
#respond_delay: 5s
|
||||||
|
|
||||||
# Cipher allows you to choose between the available ciphers for your network. Options are chachapoly or aes
|
# Cipher allows you to choose between the available ciphers for your network. Options are chachapoly or aes
|
||||||
@@ -294,24 +282,6 @@ tun:
|
|||||||
# metric: 100
|
# metric: 100
|
||||||
# install: true
|
# install: true
|
||||||
|
|
||||||
# On Windows only, sets the network category of the nebula interface. Without this, Windows often
|
|
||||||
# leaves the network as "Unidentified" and treats it as Public, which makes the host firewall more
|
|
||||||
# restrictive than you usually want for an overlay between trusted peers. Valid values:
|
|
||||||
# private - treat the nebula network as a private/trusted network (default)
|
|
||||||
# public - treat it as a public/untrusted network
|
|
||||||
# domain - treat it as a domain-authenticated network
|
|
||||||
# unset - leave whatever Windows decided alone
|
|
||||||
# Not reloadable.
|
|
||||||
#network_category: private
|
|
||||||
|
|
||||||
# On Windows only
|
|
||||||
# When true, Nebula installs a WFP (Windows Filtering Platform) PERMIT filter scoped to the nebula adapter LUID.
|
|
||||||
# WFP sits below Windows Defender Firewall, so this lets inbound traffic through regardless of WDF rules.
|
|
||||||
# Filters are auto-removed when the adapter goes away.
|
|
||||||
# See listen.windows_bypass_wdf for the matching control over inbound to nebula's outside UDP listener.
|
|
||||||
# Default true; set to false to leave WDF in charge of inbound decisions on the nebula interface. Not reloadable.
|
|
||||||
#windows_bypass_wdf: true
|
|
||||||
|
|
||||||
# On linux only, set to true to manage unsafe routes directly on the system route table with gateway routes instead of
|
# On linux only, set to true to manage unsafe routes directly on the system route table with gateway routes instead of
|
||||||
# in nebula configuration files. Default false, not reloadable.
|
# in nebula configuration files. Default false, not reloadable.
|
||||||
#use_system_route_table: false
|
#use_system_route_table: false
|
||||||
|
|||||||
+2
-4
@@ -5,8 +5,6 @@ import (
|
|||||||
"log/slog"
|
"log/slog"
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/slackhq/nebula/logging"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// ConntrackCache is used as a local routine cache to know if a given flow
|
// ConntrackCache is used as a local routine cache to know if a given flow
|
||||||
@@ -58,8 +56,8 @@ func (c *ConntrackCacheTicker) Get() ConntrackCache {
|
|||||||
if tick := c.cacheTick.Load(); tick != c.cacheV {
|
if tick := c.cacheTick.Load(); tick != c.cacheV {
|
||||||
c.cacheV = tick
|
c.cacheV = tick
|
||||||
if ll := len(c.cache); ll > 0 {
|
if ll := len(c.cache); ll > 0 {
|
||||||
if c.l.Enabled(context.Background(), logging.LevelTrace) {
|
if c.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
c.l.Log(context.Background(), logging.LevelTrace, "resetting conntrack cache", "len", ll)
|
c.l.Debug("resetting conntrack cache", "len", ll)
|
||||||
}
|
}
|
||||||
c.cache = make(ConntrackCache, ll)
|
c.cache = make(ConntrackCache, ll)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -6,7 +6,6 @@ import (
|
|||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/slackhq/nebula/logging"
|
|
||||||
"github.com/slackhq/nebula/test"
|
"github.com/slackhq/nebula/test"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
)
|
)
|
||||||
@@ -31,27 +30,27 @@ func newFixedTicker(t *testing.T, l *slog.Logger, cacheLen int) *ConntrackCacheT
|
|||||||
|
|
||||||
func TestConntrackCacheTicker_Get_TextFormat(t *testing.T) {
|
func TestConntrackCacheTicker_Get_TextFormat(t *testing.T) {
|
||||||
buf := &bytes.Buffer{}
|
buf := &bytes.Buffer{}
|
||||||
l := test.NewLoggerWithOutputAndLevel(buf, logging.LevelTrace)
|
l := test.NewLoggerWithOutputAndLevel(buf, slog.LevelDebug)
|
||||||
|
|
||||||
c := newFixedTicker(t, l, 3)
|
c := newFixedTicker(t, l, 3)
|
||||||
c.Get()
|
c.Get()
|
||||||
|
|
||||||
assert.Equal(t, "level=DEBUG-4 msg=\"resetting conntrack cache\" len=3\n", buf.String())
|
assert.Equal(t, "level=DEBUG msg=\"resetting conntrack cache\" len=3\n", buf.String())
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestConntrackCacheTicker_Get_JSONFormat(t *testing.T) {
|
func TestConntrackCacheTicker_Get_JSONFormat(t *testing.T) {
|
||||||
buf := &bytes.Buffer{}
|
buf := &bytes.Buffer{}
|
||||||
l := test.NewJSONLoggerWithOutput(buf, logging.LevelTrace)
|
l := test.NewJSONLoggerWithOutput(buf, slog.LevelDebug)
|
||||||
|
|
||||||
c := newFixedTicker(t, l, 2)
|
c := newFixedTicker(t, l, 2)
|
||||||
c.Get()
|
c.Get()
|
||||||
|
|
||||||
assert.JSONEq(t, `{"level":"DEBUG-4","msg":"resetting conntrack cache","len":2}`, strings.TrimSpace(buf.String()))
|
assert.JSONEq(t, `{"level":"DEBUG","msg":"resetting conntrack cache","len":2}`, strings.TrimSpace(buf.String()))
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestConntrackCacheTicker_Get_QuietBelowTrace(t *testing.T) {
|
func TestConntrackCacheTicker_Get_QuietBelowDebug(t *testing.T) {
|
||||||
buf := &bytes.Buffer{}
|
buf := &bytes.Buffer{}
|
||||||
l := test.NewLoggerWithOutputAndLevel(buf, slog.LevelDebug)
|
l := test.NewLoggerWithOutputAndLevel(buf, slog.LevelInfo)
|
||||||
|
|
||||||
c := newFixedTicker(t, l, 5)
|
c := newFixedTicker(t, l, 5)
|
||||||
c.Get()
|
c.Get()
|
||||||
@@ -61,7 +60,7 @@ func TestConntrackCacheTicker_Get_QuietBelowTrace(t *testing.T) {
|
|||||||
|
|
||||||
func TestConntrackCacheTicker_Get_QuietWhenCacheEmpty(t *testing.T) {
|
func TestConntrackCacheTicker_Get_QuietWhenCacheEmpty(t *testing.T) {
|
||||||
buf := &bytes.Buffer{}
|
buf := &bytes.Buffer{}
|
||||||
l := test.NewLoggerWithOutputAndLevel(buf, logging.LevelTrace)
|
l := test.NewLoggerWithOutputAndLevel(buf, slog.LevelDebug)
|
||||||
|
|
||||||
c := newFixedTicker(t, l, 0)
|
c := newFixedTicker(t, l, 0)
|
||||||
c.Get()
|
c.Get()
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ require (
|
|||||||
github.com/armon/go-radix v1.0.0
|
github.com/armon/go-radix v1.0.0
|
||||||
github.com/cyberdelia/go-metrics-graphite v0.0.0-20161219230853-39f87cc3b432
|
github.com/cyberdelia/go-metrics-graphite v0.0.0-20161219230853-39f87cc3b432
|
||||||
github.com/flynn/noise v1.1.0
|
github.com/flynn/noise v1.1.0
|
||||||
github.com/gaissmai/bart v0.26.1
|
github.com/gaissmai/bart v0.26.0
|
||||||
github.com/gogo/protobuf v1.3.2
|
github.com/gogo/protobuf v1.3.2
|
||||||
github.com/google/gopacket v1.1.19
|
github.com/google/gopacket v1.1.19
|
||||||
github.com/kardianos/service v1.2.4
|
github.com/kardianos/service v1.2.4
|
||||||
@@ -26,7 +26,7 @@ require (
|
|||||||
go.yaml.in/yaml/v3 v3.0.4
|
go.yaml.in/yaml/v3 v3.0.4
|
||||||
golang.org/x/crypto v0.50.0
|
golang.org/x/crypto v0.50.0
|
||||||
golang.org/x/exp v0.0.0-20230725093048-515e97ebf090
|
golang.org/x/exp v0.0.0-20230725093048-515e97ebf090
|
||||||
golang.org/x/net v0.53.0
|
golang.org/x/net v0.52.0
|
||||||
golang.org/x/sync v0.20.0
|
golang.org/x/sync v0.20.0
|
||||||
golang.org/x/sys v0.43.0
|
golang.org/x/sys v0.43.0
|
||||||
golang.org/x/term v0.42.0
|
golang.org/x/term v0.42.0
|
||||||
|
|||||||
@@ -26,8 +26,8 @@ github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c
|
|||||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
github.com/flynn/noise v1.1.0 h1:KjPQoQCEFdZDiP03phOvGi11+SVVhBG2wOWAorLsstg=
|
github.com/flynn/noise v1.1.0 h1:KjPQoQCEFdZDiP03phOvGi11+SVVhBG2wOWAorLsstg=
|
||||||
github.com/flynn/noise v1.1.0/go.mod h1:xbMo+0i6+IGbYdJhF31t2eR1BIU0CYc12+BNAKwUTag=
|
github.com/flynn/noise v1.1.0/go.mod h1:xbMo+0i6+IGbYdJhF31t2eR1BIU0CYc12+BNAKwUTag=
|
||||||
github.com/gaissmai/bart v0.26.1 h1:+w4rnLGNlA2GDVn382Tfe3jOsK5vOr5n4KmigJ9lbTo=
|
github.com/gaissmai/bart v0.26.0 h1:xOZ57E9hJLBiQaSyeZa9wgWhGuzfGACgqp4BE77OkO0=
|
||||||
github.com/gaissmai/bart v0.26.1/go.mod h1:GREWQfTLRWz/c5FTOsIw+KkscuFkIV5t8Rp7Nd1Td5c=
|
github.com/gaissmai/bart v0.26.0/go.mod h1:GREWQfTLRWz/c5FTOsIw+KkscuFkIV5t8Rp7Nd1Td5c=
|
||||||
github.com/go-kit/kit v0.8.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
|
github.com/go-kit/kit v0.8.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
|
||||||
github.com/go-kit/kit v0.9.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
|
github.com/go-kit/kit v0.9.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
|
||||||
github.com/go-kit/log v0.1.0/go.mod h1:zbhenjAZHb184qTLMA9ZjW7ThYL0H2mk7Q6pNt4vbaY=
|
github.com/go-kit/log v0.1.0/go.mod h1:zbhenjAZHb184qTLMA9ZjW7ThYL0H2mk7Q6pNt4vbaY=
|
||||||
@@ -182,8 +182,8 @@ golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLL
|
|||||||
golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
|
golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
|
||||||
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
|
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
|
||||||
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
|
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
|
||||||
golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA=
|
golang.org/x/net v0.52.0 h1:He/TN1l0e4mmR3QqHMT2Xab3Aj3L9qjbhRm78/6jrW0=
|
||||||
golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs=
|
golang.org/x/net v0.52.0/go.mod h1:R1MAz7uMZxVMualyPXb+VaqGSa3LIaUqk0eEt3w36Sw=
|
||||||
golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
|
golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
|
||||||
golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
golang.org/x/sync v0.0.0-20181221193216-37e7f081c4d4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20181221193216-37e7f081c4d4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
|
|||||||
@@ -31,7 +31,6 @@ type CertVerifier func(cert.Certificate) (*cert.CachedCertificate, error)
|
|||||||
type Result struct {
|
type Result struct {
|
||||||
EKey *noise.CipherState
|
EKey *noise.CipherState
|
||||||
DKey *noise.CipherState
|
DKey *noise.CipherState
|
||||||
Cipher noise.CipherFunc // identifies which post-handshake CipherState the data plane should wrap EKey/DKey in
|
|
||||||
MyCert cert.Certificate
|
MyCert cert.Certificate
|
||||||
RemoteCert *cert.CachedCertificate
|
RemoteCert *cert.CachedCertificate
|
||||||
RemoteIndex uint32
|
RemoteIndex uint32
|
||||||
@@ -106,7 +105,6 @@ func NewMachine(
|
|||||||
myVersion: version,
|
myVersion: version,
|
||||||
result: &Result{
|
result: &Result{
|
||||||
Initiator: initiator,
|
Initiator: initiator,
|
||||||
Cipher: cred.cipherSuite,
|
|
||||||
},
|
},
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -974,7 +974,6 @@ func (hm *HandshakeManager) continueHandshake(via ViaSender, hh *HandshakeHostIn
|
|||||||
nb := make([]byte, 12, 12)
|
nb := make([]byte, 12, 12)
|
||||||
out := make([]byte, mtu)
|
out := make([]byte, mtu)
|
||||||
for _, cp := range hh.packetStore {
|
for _, cp := range hh.packetStore {
|
||||||
//todo use a sendbatcher
|
|
||||||
cp.callback(cp.messageType, cp.messageSubType, hostinfo, cp.packet, nb, out)
|
cp.callback(cp.messageType, cp.messageSubType, hostinfo, cp.packet, nb, out)
|
||||||
}
|
}
|
||||||
f.cachedPacketMetrics.sent.Inc(int64(len(hh.packetStore)))
|
f.cachedPacketMetrics.sent.Inc(int64(len(hh.packetStore)))
|
||||||
|
|||||||
+8
-18
@@ -55,8 +55,10 @@ const (
|
|||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
TestRequest MessageSubType = 0
|
TestRequest MessageSubType = 0
|
||||||
TestReply MessageSubType = 1
|
TestReply MessageSubType = 1
|
||||||
|
MTUDProbeRequest MessageSubType = 2
|
||||||
|
MTUDProbeReply MessageSubType = 3
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
@@ -67,8 +69,10 @@ const (
|
|||||||
var ErrHeaderTooShort = errors.New("header is too short")
|
var ErrHeaderTooShort = errors.New("header is too short")
|
||||||
|
|
||||||
var subTypeTestMap = map[MessageSubType]string{
|
var subTypeTestMap = map[MessageSubType]string{
|
||||||
TestRequest: "testRequest",
|
TestRequest: "testRequest",
|
||||||
TestReply: "testReply",
|
TestReply: "testReply",
|
||||||
|
MTUDProbeRequest: "mtudProbeRequest",
|
||||||
|
MTUDProbeReply: "mtudProbeReply",
|
||||||
}
|
}
|
||||||
|
|
||||||
var subTypeNoneMap = map[MessageSubType]string{0: "none"}
|
var subTypeNoneMap = map[MessageSubType]string{0: "none"}
|
||||||
@@ -174,10 +178,6 @@ func (h *H) SubTypeName() string {
|
|||||||
return SubTypeName(h.Type, h.Subtype)
|
return SubTypeName(h.Type, h.Subtype)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (h *H) IsValidSubType() bool {
|
|
||||||
return IsValidSubType(h.Type, h.Subtype)
|
|
||||||
}
|
|
||||||
|
|
||||||
// SubTypeName will transform a nebula message sub type into a human string
|
// SubTypeName will transform a nebula message sub type into a human string
|
||||||
func SubTypeName(t MessageType, s MessageSubType) string {
|
func SubTypeName(t MessageType, s MessageSubType) string {
|
||||||
if n, ok := subTypeMap[t]; ok {
|
if n, ok := subTypeMap[t]; ok {
|
||||||
@@ -189,16 +189,6 @@ func SubTypeName(t MessageType, s MessageSubType) string {
|
|||||||
return "unknown"
|
return "unknown"
|
||||||
}
|
}
|
||||||
|
|
||||||
func IsValidSubType(t MessageType, s MessageSubType) bool {
|
|
||||||
if n, ok := subTypeMap[t]; ok {
|
|
||||||
if _, ok := (*n)[s]; ok {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewHeader turns bytes into a header
|
// NewHeader turns bytes into a header
|
||||||
func NewHeader(b []byte) (*H, error) {
|
func NewHeader(b []byte) (*H, error) {
|
||||||
h := new(H)
|
h := new(H)
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ package nebula
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
|
|
||||||
@@ -10,17 +9,10 @@ import (
|
|||||||
"github.com/slackhq/nebula/header"
|
"github.com/slackhq/nebula/header"
|
||||||
"github.com/slackhq/nebula/iputil"
|
"github.com/slackhq/nebula/iputil"
|
||||||
"github.com/slackhq/nebula/noiseutil"
|
"github.com/slackhq/nebula/noiseutil"
|
||||||
"github.com/slackhq/nebula/overlay/batch"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func (f *Interface) consumeInsidePacket(pkt wire.TunPacket, fwPacket *firewall.Packet, nb []byte, sendBatch *batch.SendBatch, rejectBuf []byte, q int, localCache firewall.ConntrackCache) {
|
func (f *Interface) consumeInsidePacket(packet []byte, fwPacket *firewall.Packet, nb, out []byte, q int, localCache firewall.ConntrackCache) {
|
||||||
// pkt.Bytes is either one IP datagram (GSO zero) or a TSO/USO
|
|
||||||
// superpacket. In both cases the L3+L4 headers at the start describe
|
|
||||||
// the same 5-tuple every segment will share, so a single newPacket /
|
|
||||||
// firewall check covers the whole superpacket.
|
|
||||||
packet := pkt.Bytes
|
|
||||||
err := newPacket(packet, false, fwPacket)
|
err := newPacket(packet, false, fwPacket)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
@@ -45,10 +37,7 @@ func (f *Interface) consumeInsidePacket(pkt wire.TunPacket, fwPacket *firewall.P
|
|||||||
// routes packets from the Nebula addr to the Nebula addr through the Nebula
|
// routes packets from the Nebula addr to the Nebula addr through the Nebula
|
||||||
// TUN device.
|
// TUN device.
|
||||||
if immediatelyForwardToSelf {
|
if immediatelyForwardToSelf {
|
||||||
err := pkt.PerSegment(func(seg []byte) error {
|
_, err := f.readers[q].Write(packet)
|
||||||
_, werr := f.readers[q].Write(seg)
|
|
||||||
return werr
|
|
||||||
})
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
f.l.Error("Failed to forward to tun", "error", err)
|
f.l.Error("Failed to forward to tun", "error", err)
|
||||||
}
|
}
|
||||||
@@ -64,23 +53,11 @@ func (f *Interface) consumeInsidePacket(pkt wire.TunPacket, fwPacket *firewall.P
|
|||||||
}
|
}
|
||||||
|
|
||||||
hostinfo, ready := f.getOrHandshakeConsiderRouting(fwPacket, func(hh *HandshakeHostInfo) {
|
hostinfo, ready := f.getOrHandshakeConsiderRouting(fwPacket, func(hh *HandshakeHostInfo) {
|
||||||
// borrowed: PerSegment builds each segment in the kernel-supplied pkt
|
hh.cachePacket(f.l, header.Message, 0, packet, f.sendMessageNow, f.cachedPacketMetrics)
|
||||||
// bytes underneath. cachePacket explicitly copies its argument (handshake_manager.go cachePacket),
|
|
||||||
// so retaining segments past the loop is safe.
|
|
||||||
err := pkt.PerSegment(func(seg []byte) error {
|
|
||||||
hh.cachePacket(f.l, header.Message, 0, seg, f.sendMessageNow, f.cachedPacketMetrics)
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err != nil && f.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
f.l.Debug("Failed to segment superpacket for handshake cache",
|
|
||||||
"error", err,
|
|
||||||
"vpnAddr", fwPacket.RemoteAddr,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
})
|
})
|
||||||
|
|
||||||
if hostinfo == nil {
|
if hostinfo == nil {
|
||||||
f.rejectInside(packet, rejectBuf, q)
|
f.rejectInside(packet, out, q)
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
f.l.Debug("dropping outbound packet, vpnAddr not in our vpn networks or in unsafe networks",
|
f.l.Debug("dropping outbound packet, vpnAddr not in our vpn networks or in unsafe networks",
|
||||||
"vpnAddr", fwPacket.RemoteAddr,
|
"vpnAddr", fwPacket.RemoteAddr,
|
||||||
@@ -96,9 +73,10 @@ func (f *Interface) consumeInsidePacket(pkt wire.TunPacket, fwPacket *firewall.P
|
|||||||
|
|
||||||
dropReason := f.firewall.Drop(*fwPacket, false, hostinfo, f.pki.GetCAPool(), localCache)
|
dropReason := f.firewall.Drop(*fwPacket, false, hostinfo, f.pki.GetCAPool(), localCache)
|
||||||
if dropReason == nil {
|
if dropReason == nil {
|
||||||
f.sendInsideMessage(hostinfo, pkt, nb, sendBatch)
|
f.sendNoMetrics(header.Message, 0, hostinfo.ConnectionState, hostinfo, netip.AddrPort{}, packet, nb, out, q)
|
||||||
|
|
||||||
} else {
|
} else {
|
||||||
f.rejectInside(packet, rejectBuf, q)
|
f.rejectInside(packet, out, q)
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
hostinfo.logger(f.l).Debug("dropping outbound packet",
|
hostinfo.logger(f.l).Debug("dropping outbound packet",
|
||||||
"fwPacket", fwPacket,
|
"fwPacket", fwPacket,
|
||||||
@@ -108,149 +86,6 @@ func (f *Interface) consumeInsidePacket(pkt wire.TunPacket, fwPacket *firewall.P
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *Interface) sendInsideEncrypt(hostinfo *HostInfo, ci *ConnectionState, seg, scratch, nb []byte) []byte {
|
|
||||||
if noiseutil.EncryptLockNeeded {
|
|
||||||
ci.writeLock.Lock()
|
|
||||||
}
|
|
||||||
c := ci.messageCounter.Add(1)
|
|
||||||
|
|
||||||
out := header.Encode(scratch, header.Version, header.Message, 0, hostinfo.remoteIndexId, c)
|
|
||||||
f.connectionManager.Out(hostinfo)
|
|
||||||
|
|
||||||
out, encErr := ci.eKey.EncryptDanger(out, out, seg, c, nb)
|
|
||||||
if noiseutil.EncryptLockNeeded {
|
|
||||||
ci.writeLock.Unlock()
|
|
||||||
}
|
|
||||||
if encErr != nil {
|
|
||||||
hostinfo.logger(f.l).Error("Failed to encrypt outgoing packet",
|
|
||||||
"error", encErr,
|
|
||||||
"udpAddr", hostinfo.remote,
|
|
||||||
"counter", c,
|
|
||||||
)
|
|
||||||
// Skip this segment; the rest of the superpacket can still
|
|
||||||
// go out — TCP will retransmit anything we drop here.
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|
||||||
// sendInsideMessage encrypts a firewall-approved inside packet (or every
|
|
||||||
// segment of a TSO/USO superpacket) into the caller's batch slot for
|
|
||||||
// later sendmmsg flush. Segmentation is fused with encryption here so the
|
|
||||||
// kernel-supplied superpacket bytes never get written into a separate
|
|
||||||
// scratch arena: PerSegment builds each segment's plaintext in
|
|
||||||
// segScratch[:segLen] in turn, and we encrypt directly into a fresh
|
|
||||||
// SendBatch slot.
|
|
||||||
func (f *Interface) sendInsideMessage(hostinfo *HostInfo, pkt wire.TunPacket, nb []byte, sendBatch *batch.SendBatch) {
|
|
||||||
ci := hostinfo.ConnectionState
|
|
||||||
if ci.eKey == nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
ecnEnabled := f.ecnEnabled.Load()
|
|
||||||
if hostinfo.lastRebindCount != f.rebindCount {
|
|
||||||
//NOTE: there is an update hole if a tunnel isn't used and exactly 256 rebinds occur before the tunnel is
|
|
||||||
// finally used again. This tunnel would eventually be torn down and recreated if this action didn't help.
|
|
||||||
f.lightHouse.QueryServer(hostinfo.vpnAddrs[0])
|
|
||||||
hostinfo.lastRebindCount = f.rebindCount
|
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
hostinfo.logger(f.l).Debug("Lighthouse update triggered for punch due to rebind counter",
|
|
||||||
"vpnAddrs", hostinfo.vpnAddrs,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if !hostinfo.remote.IsValid() { //the relay path
|
|
||||||
//first, find our relay hostinfo:
|
|
||||||
var relayHostInfo *HostInfo
|
|
||||||
var relay *Relay
|
|
||||||
var err error
|
|
||||||
for _, relayIP := range hostinfo.relayState.CopyRelayIps() {
|
|
||||||
relayHostInfo, relay, err = f.hostMap.QueryVpnAddrsRelayFor(hostinfo.vpnAddrs, relayIP)
|
|
||||||
if err != nil {
|
|
||||||
hostinfo.relayState.DeleteRelay(relayIP)
|
|
||||||
hostinfo.logger(f.l).Info("sendNoMetrics failed to find HostInfo",
|
|
||||||
"relay", relayIP,
|
|
||||||
"error", err,
|
|
||||||
)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
break
|
|
||||||
}
|
|
||||||
if relayHostInfo == nil || relay == nil {
|
|
||||||
//failure already logged
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
err = pkt.PerSegment(func(seg []byte) error {
|
|
||||||
//relay header + header + plaintext + AEAD tag (16 bytes for both AES-GCM and ChaCha20-Poly1305) + relay tag
|
|
||||||
scratch := sendBatch.Reserve(header.Len + header.Len + len(seg) + 16 + 16)
|
|
||||||
|
|
||||||
innerPacket := f.sendInsideEncrypt(hostinfo, ci, seg, scratch[header.Len:], nb)
|
|
||||||
if innerPacket == nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
//now we need to do a relay-encrypt:
|
|
||||||
toSend, err := f.prepareSendVia(relayHostInfo, relay, innerPacket, nb, scratch, true)
|
|
||||||
if err != nil {
|
|
||||||
//already logged
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var ecn byte
|
|
||||||
if ecnEnabled {
|
|
||||||
ecn = innerECN(seg)
|
|
||||||
}
|
|
||||||
sendBatch.Commit(toSend, relayHostInfo.remote, ecn)
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
hostinfo.logger(f.l).Error("Failed to segment superpacket for relay send", "error", err)
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
err := pkt.PerSegment(func(seg []byte) error {
|
|
||||||
// header + plaintext + AEAD tag (16 bytes for both AES-GCM and ChaCha20-Poly1305)
|
|
||||||
scratch := sendBatch.Reserve(header.Len + len(seg) + 16)
|
|
||||||
|
|
||||||
out := f.sendInsideEncrypt(hostinfo, ci, seg, scratch, nb)
|
|
||||||
if out == nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var ecn byte
|
|
||||||
if ecnEnabled {
|
|
||||||
ecn = innerECN(seg)
|
|
||||||
}
|
|
||||||
sendBatch.Commit(out, hostinfo.remote, ecn)
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
hostinfo.logger(f.l).Error("Failed to segment superpacket for send",
|
|
||||||
"error", err,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// innerECN returns the 2-bit IP-level ECN codepoint of an inner IPv4 or IPv6
|
|
||||||
// packet, or 0 if pkt is too short or its IP version is unrecognized. Used at
|
|
||||||
// encap to copy the inner codepoint onto the outer carrier per RFC 6040.
|
|
||||||
func innerECN(pkt []byte) byte {
|
|
||||||
if len(pkt) < 2 {
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
switch pkt[0] >> 4 {
|
|
||||||
case 4:
|
|
||||||
return pkt[1] & 0x03
|
|
||||||
case 6:
|
|
||||||
return (pkt[1] >> 4) & 0x03
|
|
||||||
}
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
func (f *Interface) rejectInside(packet []byte, out []byte, q int) {
|
func (f *Interface) rejectInside(packet []byte, out []byte, q int) {
|
||||||
if !f.firewall.InSendReject {
|
if !f.firewall.InSendReject {
|
||||||
return
|
return
|
||||||
@@ -440,13 +275,21 @@ func (f *Interface) sendTo(t header.MessageType, st header.MessageSubType, ci *C
|
|||||||
f.sendNoMetrics(t, st, ci, hostinfo, remote, p, nb, out, 0)
|
f.sendNoMetrics(t, st, ci, hostinfo, remote, p, nb, out, 0)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *Interface) prepareSendVia(via *HostInfo,
|
// SendVia sends a payload through a Relay tunnel. No authentication or encryption is done
|
||||||
|
// to the payload for the ultimate target host, making this a useful method for sending
|
||||||
|
// handshake messages to peers through relay tunnels.
|
||||||
|
// via is the HostInfo through which the message is relayed.
|
||||||
|
// ad is the plaintext data to authenticate, but not encrypt
|
||||||
|
// nb is a buffer used to store the nonce value, re-used for performance reasons.
|
||||||
|
// out is a buffer used to store the result of the Encrypt operation
|
||||||
|
// q indicates which writer to use to send the packet.
|
||||||
|
func (f *Interface) SendVia(via *HostInfo,
|
||||||
relay *Relay,
|
relay *Relay,
|
||||||
ad,
|
ad,
|
||||||
nb,
|
nb,
|
||||||
out []byte,
|
out []byte,
|
||||||
nocopy bool,
|
nocopy bool,
|
||||||
) ([]byte, error) {
|
) {
|
||||||
if noiseutil.EncryptLockNeeded {
|
if noiseutil.EncryptLockNeeded {
|
||||||
// NOTE: for goboring AESGCMTLS we need to lock because of the nonce check
|
// NOTE: for goboring AESGCMTLS we need to lock because of the nonce check
|
||||||
via.ConnectionState.writeLock.Lock()
|
via.ConnectionState.writeLock.Lock()
|
||||||
@@ -468,7 +311,7 @@ func (f *Interface) prepareSendVia(via *HostInfo,
|
|||||||
"headerLen", len(out),
|
"headerLen", len(out),
|
||||||
"cipherOverhead", via.ConnectionState.eKey.Overhead(),
|
"cipherOverhead", via.ConnectionState.eKey.Overhead(),
|
||||||
)
|
)
|
||||||
return nil, io.ErrShortBuffer
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// The header bytes are written to the 'out' slice; Grow the slice to hold the header and associated data payload.
|
// The header bytes are written to the 'out' slice; Grow the slice to hold the header and associated data payload.
|
||||||
@@ -488,37 +331,13 @@ func (f *Interface) prepareSendVia(via *HostInfo,
|
|||||||
}
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
via.logger(f.l).Info("Failed to EncryptDanger in sendVia", "error", err)
|
via.logger(f.l).Info("Failed to EncryptDanger in sendVia", "error", err)
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
f.connectionManager.RelayUsed(relay.LocalIndex)
|
|
||||||
return out, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// SendVia sends a payload through a Relay tunnel. No authentication or encryption is done
|
|
||||||
// to the payload for the ultimate target host, making this a useful method for sending
|
|
||||||
// handshake messages to peers through relay tunnels.
|
|
||||||
// via is the HostInfo through which the message is relayed.
|
|
||||||
// ad is the plaintext data to authenticate, but not encrypt
|
|
||||||
// nb is a buffer used to store the nonce value, re-used for performance reasons.
|
|
||||||
// out is a buffer used to store the result of the Encrypt operation.
|
|
||||||
// The write goes through writers[0] — SendVia is called from contexts
|
|
||||||
// without a per-queue index (handshake, async control paths).
|
|
||||||
func (f *Interface) SendVia(via *HostInfo,
|
|
||||||
relay *Relay,
|
|
||||||
ad,
|
|
||||||
nb,
|
|
||||||
out []byte,
|
|
||||||
nocopy bool,
|
|
||||||
) {
|
|
||||||
toSend, err := f.prepareSendVia(via, relay, ad, nb, out, nocopy)
|
|
||||||
if err != nil {
|
|
||||||
via.logger(f.l).Info("Failed to prepareSendVia", "error", err)
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
err = f.writers[0].WriteTo(toSend, via.remote)
|
err = f.writers[0].WriteTo(out, via.remote)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
via.logger(f.l).Info("Failed to WriteTo in sendVia", "error", err)
|
via.logger(f.l).Info("Failed to WriteTo in sendVia", "error", err)
|
||||||
}
|
}
|
||||||
|
f.connectionManager.RelayUsed(relay.LocalIndex)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *Interface) sendNoMetrics(t header.MessageType, st header.MessageSubType, ci *ConnectionState, hostinfo *HostInfo, remote netip.AddrPort, p, nb, out []byte, q int) {
|
func (f *Interface) sendNoMetrics(t header.MessageType, st header.MessageSubType, ci *ConnectionState, hostinfo *HostInfo, remote netip.AddrPort, p, nb, out []byte, q int) {
|
||||||
|
|||||||
+25
-113
@@ -4,24 +4,20 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"runtime"
|
|
||||||
"sync"
|
"sync"
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/rcrowley/go-metrics"
|
"github.com/rcrowley/go-metrics"
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/firewall"
|
"github.com/slackhq/nebula/firewall"
|
||||||
"github.com/slackhq/nebula/header"
|
"github.com/slackhq/nebula/header"
|
||||||
"github.com/slackhq/nebula/overlay"
|
"github.com/slackhq/nebula/overlay"
|
||||||
"github.com/slackhq/nebula/overlay/batch"
|
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/udp"
|
"github.com/slackhq/nebula/udp"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -38,10 +34,10 @@ type InterfaceConfig struct {
|
|||||||
HandshakeManager *HandshakeManager
|
HandshakeManager *HandshakeManager
|
||||||
lightHouse *LightHouse
|
lightHouse *LightHouse
|
||||||
connectionManager *connectionManager
|
connectionManager *connectionManager
|
||||||
|
pmtudManager *pmtudManager
|
||||||
DropLocalBroadcast bool
|
DropLocalBroadcast bool
|
||||||
DropMulticast bool
|
DropMulticast bool
|
||||||
routines int
|
routines int
|
||||||
batchSize int
|
|
||||||
MessageMetrics *MessageMetrics
|
MessageMetrics *MessageMetrics
|
||||||
version string
|
version string
|
||||||
relayManager *relayManager
|
relayManager *relayManager
|
||||||
@@ -52,14 +48,7 @@ type InterfaceConfig struct {
|
|||||||
reQueryWait time.Duration
|
reQueryWait time.Duration
|
||||||
|
|
||||||
ConntrackCacheTimeout time.Duration
|
ConntrackCacheTimeout time.Duration
|
||||||
|
l *slog.Logger
|
||||||
// CpuAffinity, when non-empty, names the CPUs each TUN reader goroutine
|
|
||||||
// should pin to. Queue i pins to CpuAffinity[i % len(CpuAffinity)] —
|
|
||||||
// shorter lists than `routines` cycle. Empty list keeps the default
|
|
||||||
// pin-to-(i % NumCPU) behavior.
|
|
||||||
CpuAffinity []int
|
|
||||||
|
|
||||||
l *slog.Logger
|
|
||||||
}
|
}
|
||||||
|
|
||||||
type Interface struct {
|
type Interface struct {
|
||||||
@@ -69,6 +58,7 @@ type Interface struct {
|
|||||||
pki *PKI
|
pki *PKI
|
||||||
firewall *Firewall
|
firewall *Firewall
|
||||||
connectionManager *connectionManager
|
connectionManager *connectionManager
|
||||||
|
pmtudManager *pmtudManager
|
||||||
handshakeManager *HandshakeManager
|
handshakeManager *HandshakeManager
|
||||||
dnsServer *dnsServer
|
dnsServer *dnsServer
|
||||||
createTime time.Time
|
createTime time.Time
|
||||||
@@ -81,19 +71,9 @@ type Interface struct {
|
|||||||
dropLocalBroadcast bool
|
dropLocalBroadcast bool
|
||||||
dropMulticast bool
|
dropMulticast bool
|
||||||
routines int
|
routines int
|
||||||
batchSize int
|
|
||||||
disconnectInvalid atomic.Bool
|
disconnectInvalid atomic.Bool
|
||||||
closed atomic.Bool
|
closed atomic.Bool
|
||||||
// cpuAffinity, when non-empty, names the CPUs each TUN reader goroutine
|
relayManager *relayManager
|
||||||
// should pin to. Queue i pins to cpuAffinity[i % len(cpuAffinity)].
|
|
||||||
// Empty falls back to the default pin-to-(i % NumCPU) behavior.
|
|
||||||
cpuAffinity []int
|
|
||||||
// ecnEnabled gates RFC 6040 underlay ECN propagation. When true,
|
|
||||||
// inside.go copies the inner ECN onto the outer carrier on encap and
|
|
||||||
// decryptToTun folds outer CE into the inner header on decap. Toggle
|
|
||||||
// via tunnels.ecn (default true).
|
|
||||||
ecnEnabled atomic.Bool
|
|
||||||
relayManager *relayManager
|
|
||||||
|
|
||||||
tryPromoteEvery atomic.Uint32
|
tryPromoteEvery atomic.Uint32
|
||||||
reQueryEvery atomic.Uint32
|
reQueryEvery atomic.Uint32
|
||||||
@@ -110,12 +90,8 @@ type Interface struct {
|
|||||||
|
|
||||||
ctx context.Context
|
ctx context.Context
|
||||||
writers []udp.Conn
|
writers []udp.Conn
|
||||||
readers []tio.Queue
|
readers []io.ReadWriteCloser
|
||||||
// batchers is one per tun queue, wrapping readers[i].
|
wg sync.WaitGroup
|
||||||
// decryptToTun sends plaintext into the batch.RxBatcher;
|
|
||||||
// listenOut calls its Flush at the end of each UDP recvmmsg batch.
|
|
||||||
batchers []batch.RxBatcher
|
|
||||||
wg sync.WaitGroup
|
|
||||||
|
|
||||||
// fatalErr holds the first unexpected reader error that caused shutdown.
|
// fatalErr holds the first unexpected reader error that caused shutdown.
|
||||||
// nil means "no fatal error" (yet)
|
// nil means "no fatal error" (yet)
|
||||||
@@ -211,11 +187,9 @@ func NewInterface(ctx context.Context, c *InterfaceConfig) (*Interface, error) {
|
|||||||
dropLocalBroadcast: c.DropLocalBroadcast,
|
dropLocalBroadcast: c.DropLocalBroadcast,
|
||||||
dropMulticast: c.DropMulticast,
|
dropMulticast: c.DropMulticast,
|
||||||
routines: c.routines,
|
routines: c.routines,
|
||||||
batchSize: c.batchSize,
|
|
||||||
version: c.version,
|
version: c.version,
|
||||||
writers: make([]udp.Conn, c.routines),
|
writers: make([]udp.Conn, c.routines),
|
||||||
readers: make([]tio.Queue, c.routines),
|
readers: make([]io.ReadWriteCloser, c.routines),
|
||||||
batchers: make([]batch.RxBatcher, c.routines),
|
|
||||||
myVpnNetworks: cs.myVpnNetworks,
|
myVpnNetworks: cs.myVpnNetworks,
|
||||||
myVpnNetworksTable: cs.myVpnNetworksTable,
|
myVpnNetworksTable: cs.myVpnNetworksTable,
|
||||||
myVpnAddrs: cs.myVpnAddrs,
|
myVpnAddrs: cs.myVpnAddrs,
|
||||||
@@ -223,8 +197,8 @@ func NewInterface(ctx context.Context, c *InterfaceConfig) (*Interface, error) {
|
|||||||
myBroadcastAddrsTable: cs.myVpnBroadcastAddrsTable,
|
myBroadcastAddrsTable: cs.myVpnBroadcastAddrsTable,
|
||||||
relayManager: c.relayManager,
|
relayManager: c.relayManager,
|
||||||
connectionManager: c.connectionManager,
|
connectionManager: c.connectionManager,
|
||||||
|
pmtudManager: c.pmtudManager,
|
||||||
conntrackCacheTimeout: c.ConntrackCacheTimeout,
|
conntrackCacheTimeout: c.ConntrackCacheTimeout,
|
||||||
cpuAffinity: c.CpuAffinity,
|
|
||||||
|
|
||||||
metricHandshakes: metrics.GetOrRegisterHistogram("handshakes", nil, metrics.NewExpDecaySample(1028, 0.015)),
|
metricHandshakes: metrics.GetOrRegisterHistogram("handshakes", nil, metrics.NewExpDecaySample(1028, 0.015)),
|
||||||
messageMetrics: c.MessageMetrics,
|
messageMetrics: c.MessageMetrics,
|
||||||
@@ -241,6 +215,7 @@ func NewInterface(ctx context.Context, c *InterfaceConfig) (*Interface, error) {
|
|||||||
ifce.reQueryWait.Store(int64(c.reQueryWait))
|
ifce.reQueryWait.Store(int64(c.reQueryWait))
|
||||||
|
|
||||||
ifce.connectionManager.intf = ifce
|
ifce.connectionManager.intf = ifce
|
||||||
|
ifce.pmtudManager.intf = ifce
|
||||||
|
|
||||||
return ifce, nil
|
return ifce, nil
|
||||||
}
|
}
|
||||||
@@ -274,27 +249,15 @@ func (f *Interface) activate() error {
|
|||||||
metrics.GetOrRegisterGauge("routines", nil).Update(int64(f.routines))
|
metrics.GetOrRegisterGauge("routines", nil).Update(int64(f.routines))
|
||||||
|
|
||||||
// Prepare n tun queues
|
// Prepare n tun queues
|
||||||
|
var reader io.ReadWriteCloser = f.inside
|
||||||
for i := 0; i < f.routines; i++ {
|
for i := 0; i < f.routines; i++ {
|
||||||
if i > 0 {
|
if i > 0 {
|
||||||
if err = f.inside.NewMultiQueueReader(); err != nil {
|
reader, err = f.inside.NewMultiQueueReader()
|
||||||
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
f.readers[i] = reader
|
||||||
f.readers = f.inside.Readers()
|
|
||||||
for i := range f.readers {
|
|
||||||
caps := f.readers[i].Capabilities()
|
|
||||||
if caps.TSO || caps.USO {
|
|
||||||
// Multi-lane: TCP gets coalesced when TSO is on, UDP when USO
|
|
||||||
// is on, everything else (and either lane disabled) falls
|
|
||||||
// through to passthrough so non-IP / non-TCP-UDP traffic still
|
|
||||||
// reaches the TUN.
|
|
||||||
arena := util.NewArena(max(f.batchSize, 1) * 65535)
|
|
||||||
f.batchers[i] = batch.NewMultiCoalescer(f.readers[i], f.l, arena, caps.TSO, caps.USO)
|
|
||||||
} else {
|
|
||||||
arena := util.NewArena(max(f.batchSize, 1) * udp.MTU)
|
|
||||||
f.batchers[i] = batch.NewPassthrough(f.readers[i], f.batchSize, arena)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
f.wg.Add(1) // for us to wait on Close() to return
|
f.wg.Add(1) // for us to wait on Close() to return
|
||||||
@@ -352,21 +315,14 @@ func (f *Interface) listenOut(i int) {
|
|||||||
|
|
||||||
ctCache := firewall.NewConntrackCacheTicker(f.ctx, f.l, f.conntrackCacheTimeout)
|
ctCache := firewall.NewConntrackCacheTicker(f.ctx, f.l, f.conntrackCacheTimeout)
|
||||||
lhh := f.lightHouse.NewRequestHandler()
|
lhh := f.lightHouse.NewRequestHandler()
|
||||||
|
plaintext := make([]byte, udp.MTU)
|
||||||
h := &header.H{}
|
h := &header.H{}
|
||||||
fwPacket := &firewall.Packet{}
|
fwPacket := &firewall.Packet{}
|
||||||
nb := make([]byte, 12, 12)
|
nb := make([]byte, 12, 12)
|
||||||
|
|
||||||
listener := func(fromUdpAddr netip.AddrPort, payload []byte, meta udp.RxMeta) {
|
err := li.ListenOut(func(fromUdpAddr netip.AddrPort, payload []byte) {
|
||||||
f.readOutsidePackets(ViaSender{UdpAddr: fromUdpAddr}, payload, h, fwPacket, lhh, nb, i, ctCache.Get(), meta)
|
f.readOutsidePackets(ViaSender{UdpAddr: fromUdpAddr}, plaintext[:0], payload, h, fwPacket, lhh, nb, i, ctCache.Get())
|
||||||
}
|
})
|
||||||
|
|
||||||
flusher := func() {
|
|
||||||
if err := f.batchers[i].Flush(); err != nil {
|
|
||||||
f.l.Error("Failed to flush tun coalescer", "error", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
err := li.ListenOut(listener, flusher)
|
|
||||||
|
|
||||||
if err != nil && !f.closed.Load() {
|
if err != nil && !f.closed.Load() {
|
||||||
f.l.Error("Error while reading inbound packet, closing", "error", err)
|
f.l.Error("Error while reading inbound packet, closing", "error", err)
|
||||||
@@ -376,57 +332,28 @@ func (f *Interface) listenOut(i int) {
|
|||||||
f.l.Debug("underlay reader is done", "reader", i)
|
f.l.Debug("underlay reader is done", "reader", i)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *Interface) listenIn(reader tio.Queue, q int) {
|
func (f *Interface) listenIn(reader io.ReadWriteCloser, i int) {
|
||||||
// Pinning this thread (and goroutine) to a single CPU keeps every sendmmsg from this goroutine going through the
|
packet := make([]byte, mtu)
|
||||||
// same TX ring on the nic, so the wire sees per-flow order.
|
out := make([]byte, mtu)
|
||||||
cpu := q % runtime.NumCPU()
|
|
||||||
if n := len(f.cpuAffinity); n > 0 {
|
|
||||||
cpu = f.cpuAffinity[q%n]
|
|
||||||
}
|
|
||||||
if err := util.PinThreadToCPU(cpu); err != nil {
|
|
||||||
f.l.Warn("failed to pin tun reader to CPU", "queue", q, "cpu", cpu, "err", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
const bonusInfo = 16
|
|
||||||
bufferScale := udp.MTU + bonusInfo
|
|
||||||
numTunPackets := 1
|
|
||||||
caps := reader.Capabilities()
|
|
||||||
if caps.TSO || caps.USO {
|
|
||||||
bufferScale = 65535 + bonusInfo
|
|
||||||
numTunPackets = f.batchSize
|
|
||||||
}
|
|
||||||
|
|
||||||
rejectBuf := make([]byte, mtu)
|
|
||||||
tunPackets := make([]wire.TunPacket, numTunPackets)
|
|
||||||
packetMem := make([]byte, bufferScale*numTunPackets)
|
|
||||||
|
|
||||||
arenaSize := batch.SendBatchCap * (udp.MTU + 32)
|
|
||||||
sb := batch.NewSendBatch(f.writers[q], batch.SendBatchCap, util.NewArena(arenaSize))
|
|
||||||
fwPacket := &firewall.Packet{}
|
fwPacket := &firewall.Packet{}
|
||||||
nb := make([]byte, 12, 12)
|
nb := make([]byte, 12, 12)
|
||||||
|
|
||||||
conntrackCache := firewall.NewConntrackCacheTicker(f.ctx, f.l, f.conntrackCacheTimeout)
|
conntrackCache := firewall.NewConntrackCacheTicker(f.ctx, f.l, f.conntrackCacheTimeout)
|
||||||
|
|
||||||
for {
|
for {
|
||||||
n, err := reader.Read(tunPackets, packetMem)
|
n, err := reader.Read(packet)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if !f.closed.Load() {
|
if !f.closed.Load() {
|
||||||
f.l.Error("Error while reading outbound packet, closing", "error", err, "reader", q)
|
f.l.Error("Error while reading outbound packet, closing", "error", err, "reader", i)
|
||||||
f.onFatal(err)
|
f.onFatal(err)
|
||||||
}
|
}
|
||||||
break
|
break
|
||||||
}
|
}
|
||||||
|
|
||||||
ctCache := conntrackCache.Get()
|
f.consumeInsidePacket(packet[:n], fwPacket, nb, out, i, conntrackCache.Get())
|
||||||
for i := range n {
|
|
||||||
f.consumeInsidePacket(tunPackets[i], fwPacket, nb, sb, rejectBuf, q, ctCache)
|
|
||||||
}
|
|
||||||
if err := sb.Flush(); err != nil {
|
|
||||||
f.l.Error("Failed to write outgoing batch", "error", err, "writer", q)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
f.l.Debug("overlay reader is done", "reader", q)
|
f.l.Debug("overlay reader is done", "reader", i)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *Interface) RegisterConfigChangeCallbacks(c *config.C) {
|
func (f *Interface) RegisterConfigChangeCallbacks(c *config.C) {
|
||||||
@@ -435,7 +362,6 @@ func (f *Interface) RegisterConfigChangeCallbacks(c *config.C) {
|
|||||||
c.RegisterReloadCallback(f.reloadAcceptRecvError)
|
c.RegisterReloadCallback(f.reloadAcceptRecvError)
|
||||||
c.RegisterReloadCallback(f.reloadDisconnectInvalid)
|
c.RegisterReloadCallback(f.reloadDisconnectInvalid)
|
||||||
c.RegisterReloadCallback(f.reloadMisc)
|
c.RegisterReloadCallback(f.reloadMisc)
|
||||||
c.RegisterReloadCallback(f.reloadEcn)
|
|
||||||
|
|
||||||
for _, udpConn := range f.writers {
|
for _, udpConn := range f.writers {
|
||||||
c.RegisterReloadCallback(udpConn.ReloadConfig)
|
c.RegisterReloadCallback(udpConn.ReloadConfig)
|
||||||
@@ -559,20 +485,6 @@ func (f *Interface) reloadMisc(c *config.C) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// reloadEcn syncs Interface.ecnEnabled with the tunnels.ecn config knob.
|
|
||||||
// Default is enabled (RFC 6040 normal mode); set false on the rare path
|
|
||||||
// where an underlay middlebox rewrites or drops ECN bits unpredictably.
|
|
||||||
func (f *Interface) reloadEcn(c *config.C) {
|
|
||||||
initial := c.InitialLoad()
|
|
||||||
if initial || c.HasChanged("tunnels.ecn") {
|
|
||||||
v := c.GetBool("tunnels.ecn", true)
|
|
||||||
f.ecnEnabled.Store(v)
|
|
||||||
if !initial {
|
|
||||||
f.l.Info("tunnels.ecn changed", "enabled", v)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (f *Interface) emitStats(ctx context.Context, i time.Duration) {
|
func (f *Interface) emitStats(ctx context.Context, i time.Duration) {
|
||||||
ticker := time.NewTicker(i)
|
ticker := time.NewTicker(i)
|
||||||
defer ticker.Stop()
|
defer ticker.Stop()
|
||||||
|
|||||||
+46
-6
@@ -15,6 +15,7 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
|
"github.com/rcrowley/go-metrics"
|
||||||
"github.com/slackhq/nebula/cert"
|
"github.com/slackhq/nebula/cert"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/header"
|
"github.com/slackhq/nebula/header"
|
||||||
@@ -34,6 +35,7 @@ type LightHouse struct {
|
|||||||
|
|
||||||
myVpnNetworks []netip.Prefix
|
myVpnNetworks []netip.Prefix
|
||||||
myVpnNetworksTable *bart.Lite
|
myVpnNetworksTable *bart.Lite
|
||||||
|
punchConn udp.Conn
|
||||||
punchy *Punchy
|
punchy *Punchy
|
||||||
|
|
||||||
// Local cache of answers from light houses
|
// Local cache of answers from light houses
|
||||||
@@ -73,8 +75,9 @@ type LightHouse struct {
|
|||||||
|
|
||||||
calculatedRemotes atomic.Pointer[bart.Table[[]*calculatedRemote]] // Maps VpnAddr to []*calculatedRemote
|
calculatedRemotes atomic.Pointer[bart.Table[[]*calculatedRemote]] // Maps VpnAddr to []*calculatedRemote
|
||||||
|
|
||||||
metrics *MessageMetrics
|
metrics *MessageMetrics
|
||||||
l *slog.Logger
|
metricHolepunchTx metrics.Counter
|
||||||
|
l *slog.Logger
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewLightHouseFromConfig will build a Lighthouse struct from the values provided in the config object
|
// NewLightHouseFromConfig will build a Lighthouse struct from the values provided in the config object
|
||||||
@@ -102,6 +105,7 @@ func NewLightHouseFromConfig(ctx context.Context, l *slog.Logger, c *config.C, c
|
|||||||
myVpnNetworksTable: cs.myVpnNetworksTable,
|
myVpnNetworksTable: cs.myVpnNetworksTable,
|
||||||
addrMap: make(map[netip.Addr]*RemoteList),
|
addrMap: make(map[netip.Addr]*RemoteList),
|
||||||
nebulaPort: nebulaPort,
|
nebulaPort: nebulaPort,
|
||||||
|
punchConn: pc,
|
||||||
punchy: p,
|
punchy: p,
|
||||||
updateTrigger: make(chan struct{}, 1),
|
updateTrigger: make(chan struct{}, 1),
|
||||||
queryChan: make(chan netip.Addr, c.GetUint32("handshakes.query_buffer", 64)),
|
queryChan: make(chan netip.Addr, c.GetUint32("handshakes.query_buffer", 64)),
|
||||||
@@ -114,6 +118,9 @@ func NewLightHouseFromConfig(ctx context.Context, l *slog.Logger, c *config.C, c
|
|||||||
|
|
||||||
if c.GetBool("stats.lighthouse_metrics", false) {
|
if c.GetBool("stats.lighthouse_metrics", false) {
|
||||||
h.metrics = newLighthouseMetrics()
|
h.metrics = newLighthouseMetrics()
|
||||||
|
h.metricHolepunchTx = metrics.GetOrRegisterCounter("messages.tx.holepunch", nil)
|
||||||
|
} else {
|
||||||
|
h.metricHolepunchTx = metrics.NilCounter{}
|
||||||
}
|
}
|
||||||
|
|
||||||
err := h.reload(c, true)
|
err := h.reload(c, true)
|
||||||
@@ -1399,25 +1406,58 @@ func (lhh *LightHouseHandler) handleHostPunchNotification(n *NebulaMeta, fromVpn
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
empty := []byte{0}
|
||||||
|
punch := func(vpnPeer netip.AddrPort, logVpnAddr netip.Addr) {
|
||||||
|
if !vpnPeer.IsValid() {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
go func() {
|
||||||
|
time.Sleep(lhh.lh.punchy.GetDelay())
|
||||||
|
lhh.lh.metricHolepunchTx.Inc(1)
|
||||||
|
lhh.lh.punchConn.WriteTo(empty, vpnPeer)
|
||||||
|
}()
|
||||||
|
|
||||||
|
if lhh.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
|
lhh.l.Debug("Punching",
|
||||||
|
"vpnPeer", vpnPeer,
|
||||||
|
"logVpnAddr", logVpnAddr,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
remoteAllowList := lhh.lh.GetRemoteAllowList()
|
remoteAllowList := lhh.lh.GetRemoteAllowList()
|
||||||
for _, a := range n.Details.V4AddrPorts {
|
for _, a := range n.Details.V4AddrPorts {
|
||||||
b := protoV4AddrPortToNetAddrPort(a)
|
b := protoV4AddrPortToNetAddrPort(a)
|
||||||
if remoteAllowList.Allow(detailsVpnAddr, b.Addr()) {
|
if remoteAllowList.Allow(detailsVpnAddr, b.Addr()) {
|
||||||
lhh.lh.punchy.Schedule(b, detailsVpnAddr)
|
punch(b, detailsVpnAddr)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, a := range n.Details.V6AddrPorts {
|
for _, a := range n.Details.V6AddrPorts {
|
||||||
b := protoV6AddrPortToNetAddrPort(a)
|
b := protoV6AddrPortToNetAddrPort(a)
|
||||||
if remoteAllowList.Allow(detailsVpnAddr, b.Addr()) {
|
if remoteAllowList.Allow(detailsVpnAddr, b.Addr()) {
|
||||||
lhh.lh.punchy.Schedule(b, detailsVpnAddr)
|
punch(b, detailsVpnAddr)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// This sends a nebula test packet to the host trying to contact us. In the case
|
// This sends a nebula test packet to the host trying to contact us. In the case
|
||||||
// of a double nat or other difficult scenario, this may help establish
|
// of a double nat or other difficult scenario, this may help establish
|
||||||
// a tunnel. ScheduleRespond is a no-op when punchy.respond is disabled.
|
// a tunnel.
|
||||||
lhh.lh.punchy.ScheduleRespond(detailsVpnAddr)
|
if lhh.lh.punchy.GetRespond() {
|
||||||
|
go func() {
|
||||||
|
time.Sleep(lhh.lh.punchy.GetRespondDelay())
|
||||||
|
if lhh.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
|
lhh.l.Debug("Sending a nebula test packet",
|
||||||
|
"vpnAddr", detailsVpnAddr,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
//NOTE: we have to allocate a new output buffer here since we are spawning a new goroutine
|
||||||
|
// for each punchBack packet. We should move this into a timerwheel or a single goroutine
|
||||||
|
// managed by a channel.
|
||||||
|
w.SendMessageToVpnAddr(header.Test, header.TestRequest, detailsVpnAddr, []byte(""), make([]byte, 12, 12), make([]byte, mtu))
|
||||||
|
}()
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func protoAddrToNetAddr(addr *Addr) netip.Addr {
|
func protoAddrToNetAddr(addr *Addr) netip.Addr {
|
||||||
|
|||||||
@@ -5,10 +5,7 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net"
|
"net"
|
||||||
"net/http"
|
|
||||||
_ "net/http/pprof"
|
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"runtime"
|
|
||||||
"runtime/debug"
|
"runtime/debug"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
@@ -36,9 +33,6 @@ func Main(c *config.C, configTest bool, buildVersion string, l *slog.Logger, dev
|
|||||||
buildVersion = moduleVersion()
|
buildVersion = moduleVersion()
|
||||||
}
|
}
|
||||||
|
|
||||||
//todo no merge
|
|
||||||
go http.ListenAndServe(":6060", nil)
|
|
||||||
|
|
||||||
// Print the config if in test, the exit comes later
|
// Print the config if in test, the exit comes later
|
||||||
if configTest {
|
if configTest {
|
||||||
b, err := yaml.Marshal(c.Settings)
|
b, err := yaml.Marshal(c.Settings)
|
||||||
@@ -61,7 +55,7 @@ func Main(c *config.C, configTest bool, buildVersion string, l *slog.Logger, dev
|
|||||||
}
|
}
|
||||||
l.Info("Firewall started", "firewallHashes", fw.GetRuleHashes())
|
l.Info("Firewall started", "firewallHashes", fw.GetRuleHashes())
|
||||||
|
|
||||||
ssh, err := sshd.NewSSHServer(ctx, l.With("subsystem", "sshd"))
|
ssh, err := sshd.NewSSHServer(l.With("subsystem", "sshd"))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, util.ContextualizeIfNeeded("Error while creating SSH server", err)
|
return nil, util.ContextualizeIfNeeded("Error while creating SSH server", err)
|
||||||
}
|
}
|
||||||
@@ -176,8 +170,9 @@ func Main(c *config.C, configTest bool, buildVersion string, l *slog.Logger, dev
|
|||||||
}
|
}
|
||||||
|
|
||||||
hostMap := NewHostMapFromConfig(l, c)
|
hostMap := NewHostMapFromConfig(l, c)
|
||||||
punchy := NewPunchyFromConfig(l, c, udpConns[0])
|
punchy := NewPunchyFromConfig(l, c)
|
||||||
connManager := newConnectionManagerFromConfig(l, c, hostMap, punchy)
|
connManager := newConnectionManagerFromConfig(l, c, hostMap, punchy)
|
||||||
|
pmtudMgr := newPMTUDManagerFromConfig(l, c, tun)
|
||||||
lightHouse, err := NewLightHouseFromConfig(ctx, l, c, pki.getCertState(), udpConns[0], punchy)
|
lightHouse, err := NewLightHouseFromConfig(ctx, l, c, pki.getCertState(), udpConns[0], punchy)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, util.ContextualizeIfNeeded("Failed to initialize lighthouse handler", err)
|
return nil, util.ContextualizeIfNeeded("Failed to initialize lighthouse handler", err)
|
||||||
@@ -214,6 +209,7 @@ func Main(c *config.C, configTest bool, buildVersion string, l *slog.Logger, dev
|
|||||||
DnsServer: ds,
|
DnsServer: ds,
|
||||||
HandshakeManager: handshakeManager,
|
HandshakeManager: handshakeManager,
|
||||||
connectionManager: connManager,
|
connectionManager: connManager,
|
||||||
|
pmtudManager: pmtudMgr,
|
||||||
lightHouse: lightHouse,
|
lightHouse: lightHouse,
|
||||||
tryPromoteEvery: c.GetUint32("counters.try_promote", defaultPromoteEvery),
|
tryPromoteEvery: c.GetUint32("counters.try_promote", defaultPromoteEvery),
|
||||||
reQueryEvery: c.GetUint32("counters.requery_every_packets", defaultReQueryEvery),
|
reQueryEvery: c.GetUint32("counters.requery_every_packets", defaultReQueryEvery),
|
||||||
@@ -221,13 +217,11 @@ func Main(c *config.C, configTest bool, buildVersion string, l *slog.Logger, dev
|
|||||||
DropLocalBroadcast: c.GetBool("tun.drop_local_broadcast", false),
|
DropLocalBroadcast: c.GetBool("tun.drop_local_broadcast", false),
|
||||||
DropMulticast: c.GetBool("tun.drop_multicast", false),
|
DropMulticast: c.GetBool("tun.drop_multicast", false),
|
||||||
routines: routines,
|
routines: routines,
|
||||||
batchSize: c.GetInt("listen.batch", 64),
|
|
||||||
MessageMetrics: messageMetrics,
|
MessageMetrics: messageMetrics,
|
||||||
version: buildVersion,
|
version: buildVersion,
|
||||||
relayManager: NewRelayManager(ctx, l, hostMap, c),
|
relayManager: NewRelayManager(ctx, l, hostMap, c),
|
||||||
punchy: punchy,
|
punchy: punchy,
|
||||||
ConntrackCacheTimeout: conntrackCacheTimeout,
|
ConntrackCacheTimeout: conntrackCacheTimeout,
|
||||||
CpuAffinity: parseCpuAffinity(c, l, routines),
|
|
||||||
l: l,
|
l: l,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -245,12 +239,9 @@ func Main(c *config.C, configTest bool, buildVersion string, l *slog.Logger, dev
|
|||||||
ifce.reloadDisconnectInvalid(c)
|
ifce.reloadDisconnectInvalid(c)
|
||||||
ifce.reloadSendRecvError(c)
|
ifce.reloadSendRecvError(c)
|
||||||
ifce.reloadAcceptRecvError(c)
|
ifce.reloadAcceptRecvError(c)
|
||||||
ifce.reloadEcn(c)
|
|
||||||
|
|
||||||
handshakeManager.f = ifce
|
handshakeManager.f = ifce
|
||||||
go handshakeManager.Run(ctx)
|
go handshakeManager.Run(ctx)
|
||||||
|
|
||||||
punchy.Start(ctx, ifce, hostMap, lightHouse)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
stats, err := newStatsServerFromConfig(ctx, l, c, buildVersion, configTest)
|
stats, err := newStatsServerFromConfig(ctx, l, c, buildVersion, configTest)
|
||||||
@@ -277,56 +268,10 @@ func Main(c *config.C, configTest bool, buildVersion string, l *slog.Logger, dev
|
|||||||
dnsStart: ds.Start,
|
dnsStart: ds.Start,
|
||||||
lighthouseStart: lightHouse.StartUpdateWorker,
|
lighthouseStart: lightHouse.StartUpdateWorker,
|
||||||
connectionManagerStart: connManager.Start,
|
connectionManagerStart: connManager.Start,
|
||||||
|
pmtudManagerStart: pmtudMgr.Start,
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// parseCpuAffinity reads `tun.cpu_affinity` from the config — a list of
|
|
||||||
// integer CPU IDs, one per TUN reader goroutine. Empty / unset returns nil
|
|
||||||
// (listenIn falls back to its default `i % NumCPU` pinning). Length
|
|
||||||
// mismatch with `routines` is a warning, not an error: shorter lists are
|
|
||||||
// modulo-cycled across queues, longer lists' tail is ignored. Invalid
|
|
||||||
// entries (non-integer, out of range) are also a warning and disable the
|
|
||||||
// override entirely so we don't silently pin to the wrong CPU.
|
|
||||||
func parseCpuAffinity(c *config.C, l *slog.Logger, routines int) []int {
|
|
||||||
raw := c.Get("tun.cpu_affinity")
|
|
||||||
if raw == nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
rv, ok := raw.([]any)
|
|
||||||
if !ok {
|
|
||||||
l.Warn("tun.cpu_affinity must be a list of integers; ignoring", "value", raw)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
nCPU := runtime.NumCPU()
|
|
||||||
cpus := make([]int, 0, len(rv))
|
|
||||||
for i, e := range rv {
|
|
||||||
var cpu int
|
|
||||||
switch v := e.(type) {
|
|
||||||
case int:
|
|
||||||
cpu = v
|
|
||||||
case int64:
|
|
||||||
cpu = int(v)
|
|
||||||
case float64:
|
|
||||||
cpu = int(v)
|
|
||||||
default:
|
|
||||||
l.Warn("tun.cpu_affinity entry not an integer; ignoring affinity",
|
|
||||||
"index", i, "value", e)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if cpu < 0 || cpu >= nCPU {
|
|
||||||
l.Warn("tun.cpu_affinity entry out of range; ignoring affinity",
|
|
||||||
"index", i, "cpu", cpu, "num_cpu", nCPU)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
cpus = append(cpus, cpu)
|
|
||||||
}
|
|
||||||
if len(cpus) != routines {
|
|
||||||
l.Warn("tun.cpu_affinity length doesn't match routines; queues will modulo-cycle through the list",
|
|
||||||
"affinity_len", len(cpus), "routines", routines)
|
|
||||||
}
|
|
||||||
return cpus
|
|
||||||
}
|
|
||||||
|
|
||||||
func moduleVersion() string {
|
func moduleVersion() string {
|
||||||
info, ok := debug.ReadBuildInfo()
|
info, ok := debug.ReadBuildInfo()
|
||||||
if !ok {
|
if !ok {
|
||||||
|
|||||||
@@ -13,8 +13,6 @@ type MessageMetrics struct {
|
|||||||
|
|
||||||
rxUnknown metrics.Counter
|
rxUnknown metrics.Counter
|
||||||
txUnknown metrics.Counter
|
txUnknown metrics.Counter
|
||||||
|
|
||||||
rxInvalid metrics.Counter
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (m *MessageMetrics) Rx(t header.MessageType, s header.MessageSubType, i int64) {
|
func (m *MessageMetrics) Rx(t header.MessageType, s header.MessageSubType, i int64) {
|
||||||
@@ -35,11 +33,6 @@ func (m *MessageMetrics) Tx(t header.MessageType, s header.MessageSubType, i int
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
func (m *MessageMetrics) RxInvalid(i int64) {
|
|
||||||
if m != nil && m.rxInvalid != nil {
|
|
||||||
m.rxInvalid.Inc(i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func newMessageMetrics() *MessageMetrics {
|
func newMessageMetrics() *MessageMetrics {
|
||||||
gen := func(t string) [][]metrics.Counter {
|
gen := func(t string) [][]metrics.Counter {
|
||||||
@@ -63,7 +56,6 @@ func newMessageMetrics() *MessageMetrics {
|
|||||||
|
|
||||||
rxUnknown: metrics.GetOrRegisterCounter("messages.rx.other", nil),
|
rxUnknown: metrics.GetOrRegisterCounter("messages.rx.other", nil),
|
||||||
txUnknown: metrics.GetOrRegisterCounter("messages.tx.other", nil),
|
txUnknown: metrics.GetOrRegisterCounter("messages.tx.other", nil),
|
||||||
rxInvalid: metrics.GetOrRegisterCounter("messages.rx.invalid", nil),
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,73 @@
|
|||||||
|
package nebula
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/cipher"
|
||||||
|
"encoding/binary"
|
||||||
|
"errors"
|
||||||
|
|
||||||
|
"github.com/flynn/noise"
|
||||||
|
)
|
||||||
|
|
||||||
|
type endianness interface {
|
||||||
|
PutUint64(b []byte, v uint64)
|
||||||
|
}
|
||||||
|
|
||||||
|
var noiseEndianness endianness = binary.BigEndian
|
||||||
|
|
||||||
|
type NebulaCipherState struct {
|
||||||
|
c cipher.AEAD
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewNebulaCipherState(s *noise.CipherState) *NebulaCipherState {
|
||||||
|
x := s.Cipher()
|
||||||
|
return &NebulaCipherState{c: x.(cipher.AEAD)}
|
||||||
|
}
|
||||||
|
|
||||||
|
// EncryptDanger encrypts and authenticates a given payload.
|
||||||
|
//
|
||||||
|
// out is a destination slice to hold the output of the EncryptDanger operation.
|
||||||
|
// - ad is additional data, which will be authenticated and appended to out, but not encrypted.
|
||||||
|
// - plaintext is encrypted, authenticated and appended to out.
|
||||||
|
// - n is a nonce value which must never be re-used with this key.
|
||||||
|
// - nb is a buffer used for temporary storage in the implementation of this call, which should
|
||||||
|
// be re-used by callers to minimize garbage collection.
|
||||||
|
func (s *NebulaCipherState) EncryptDanger(out, ad, plaintext []byte, n uint64, nb []byte) ([]byte, error) {
|
||||||
|
if s != nil {
|
||||||
|
// TODO: Is this okay now that we have made messageCounter atomic?
|
||||||
|
// Alternative may be to split the counter space into ranges
|
||||||
|
//if n <= s.n {
|
||||||
|
// return nil, errors.New("CRITICAL: a duplicate counter value was used")
|
||||||
|
//}
|
||||||
|
//s.n = n
|
||||||
|
nb[0] = 0
|
||||||
|
nb[1] = 0
|
||||||
|
nb[2] = 0
|
||||||
|
nb[3] = 0
|
||||||
|
noiseEndianness.PutUint64(nb[4:], n)
|
||||||
|
out = s.c.Seal(out, nb, plaintext, ad)
|
||||||
|
//l.Debugf("Encryption: outlen: %d, nonce: %d, ad: %s, plainlen %d", len(out), n, ad, len(plaintext))
|
||||||
|
return out, nil
|
||||||
|
} else {
|
||||||
|
return nil, errors.New("no cipher state available to encrypt")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *NebulaCipherState) DecryptDanger(out, ad, ciphertext []byte, n uint64, nb []byte) ([]byte, error) {
|
||||||
|
if s != nil {
|
||||||
|
nb[0] = 0
|
||||||
|
nb[1] = 0
|
||||||
|
nb[2] = 0
|
||||||
|
nb[3] = 0
|
||||||
|
noiseEndianness.PutUint64(nb[4:], n)
|
||||||
|
return s.c.Open(out, nb, ciphertext, ad)
|
||||||
|
} else {
|
||||||
|
return []byte{}, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *NebulaCipherState) Overhead() int {
|
||||||
|
if s != nil {
|
||||||
|
return s.c.Overhead()
|
||||||
|
}
|
||||||
|
return 0
|
||||||
|
}
|
||||||
@@ -1,53 +0,0 @@
|
|||||||
package noiseutil
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/cipher"
|
|
||||||
"encoding/binary"
|
|
||||||
"errors"
|
|
||||||
|
|
||||||
"github.com/flynn/noise"
|
|
||||||
)
|
|
||||||
|
|
||||||
// CipherStateAESGCM is the data-plane wrapper for the AES-GCM AEAD cipher.
|
|
||||||
// AES-GCM uses big-endian nonce encoding per the Noise spec.
|
|
||||||
type CipherStateAESGCM struct {
|
|
||||||
c cipher.AEAD
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewCipherStateAESGCM extracts the underlying AEAD from the post-handshake noise.CipherState.
|
|
||||||
// The caller is responsible for ensuring the noise cipher is actually AES-GCM,
|
|
||||||
// otherwise the type assertion still succeeds but the nonce endianness will be wrong on the wire.
|
|
||||||
func NewCipherStateAESGCM(s *noise.CipherState) *CipherStateAESGCM {
|
|
||||||
return &CipherStateAESGCM{c: s.Cipher().(cipher.AEAD)}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CipherStateAESGCM) EncryptDanger(out, ad, plaintext []byte, n uint64, nb []byte) ([]byte, error) {
|
|
||||||
if s == nil {
|
|
||||||
return nil, errors.New("no cipher state available to encrypt")
|
|
||||||
}
|
|
||||||
nb[0] = 0
|
|
||||||
nb[1] = 0
|
|
||||||
nb[2] = 0
|
|
||||||
nb[3] = 0
|
|
||||||
binary.BigEndian.PutUint64(nb[4:], n)
|
|
||||||
return s.c.Seal(out, nb, plaintext, ad), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CipherStateAESGCM) DecryptDanger(out, ad, ciphertext []byte, n uint64, nb []byte) ([]byte, error) {
|
|
||||||
if s == nil {
|
|
||||||
return []byte{}, nil
|
|
||||||
}
|
|
||||||
nb[0] = 0
|
|
||||||
nb[1] = 0
|
|
||||||
nb[2] = 0
|
|
||||||
nb[3] = 0
|
|
||||||
binary.BigEndian.PutUint64(nb[4:], n)
|
|
||||||
return s.c.Open(out, nb, ciphertext, ad)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CipherStateAESGCM) Overhead() int {
|
|
||||||
if s == nil {
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
return s.c.Overhead()
|
|
||||||
}
|
|
||||||
@@ -1,52 +0,0 @@
|
|||||||
package noiseutil
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/cipher"
|
|
||||||
"encoding/binary"
|
|
||||||
"errors"
|
|
||||||
|
|
||||||
"github.com/flynn/noise"
|
|
||||||
)
|
|
||||||
|
|
||||||
// CipherStateChaChaPoly is the data-plane wrapper for the ChaCha20-Poly1305 AEAD cipher.
|
|
||||||
// ChaCha20-Poly1305 uses little-endian nonce encoding per the Noise spec.
|
|
||||||
type CipherStateChaChaPoly struct {
|
|
||||||
c cipher.AEAD
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewCipherStateChaChaPoly extracts the underlying AEAD from the post-handshake noise.CipherState.
|
|
||||||
// The caller is responsible for ensuring the noise cipher is actually ChaCha20-Poly1305.
|
|
||||||
func NewCipherStateChaChaPoly(s *noise.CipherState) *CipherStateChaChaPoly {
|
|
||||||
return &CipherStateChaChaPoly{c: s.Cipher().(cipher.AEAD)}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CipherStateChaChaPoly) EncryptDanger(out, ad, plaintext []byte, n uint64, nb []byte) ([]byte, error) {
|
|
||||||
if s == nil {
|
|
||||||
return nil, errors.New("no cipher state available to encrypt")
|
|
||||||
}
|
|
||||||
nb[0] = 0
|
|
||||||
nb[1] = 0
|
|
||||||
nb[2] = 0
|
|
||||||
nb[3] = 0
|
|
||||||
binary.LittleEndian.PutUint64(nb[4:], n)
|
|
||||||
return s.c.Seal(out, nb, plaintext, ad), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CipherStateChaChaPoly) DecryptDanger(out, ad, ciphertext []byte, n uint64, nb []byte) ([]byte, error) {
|
|
||||||
if s == nil {
|
|
||||||
return []byte{}, nil
|
|
||||||
}
|
|
||||||
nb[0] = 0
|
|
||||||
nb[1] = 0
|
|
||||||
nb[2] = 0
|
|
||||||
nb[3] = 0
|
|
||||||
binary.LittleEndian.PutUint64(nb[4:], n)
|
|
||||||
return s.c.Open(out, nb, ciphertext, ad)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CipherStateChaChaPoly) Overhead() int {
|
|
||||||
if s == nil {
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
return s.c.Overhead()
|
|
||||||
}
|
|
||||||
@@ -1,40 +0,0 @@
|
|||||||
package noiseutil
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
|
|
||||||
"github.com/flynn/noise"
|
|
||||||
)
|
|
||||||
|
|
||||||
// CipherState is the post-handshake AEAD cipher used for the data plane.
|
|
||||||
// Each supported cipher has its own concrete implementation in this package with the nonce endianness hardcoded,
|
|
||||||
// so the encrypt/decrypt fast path avoids interface dispatch on the byte order.
|
|
||||||
type CipherState interface {
|
|
||||||
// EncryptDanger encrypts and authenticates a given payload.
|
|
||||||
//
|
|
||||||
// out is a destination slice to hold the output of the EncryptDanger operation.
|
|
||||||
// - ad is additional data, which will be authenticated and appended to out, but not encrypted.
|
|
||||||
// - plaintext is encrypted, authenticated and appended to out.
|
|
||||||
// - n is a nonce value which must never be re-used with this key.
|
|
||||||
// - nb is a scratch buffer used to assemble the nonce.
|
|
||||||
EncryptDanger(out, ad, plaintext []byte, n uint64, nb []byte) ([]byte, error)
|
|
||||||
|
|
||||||
// DecryptDanger authenticates and decrypts a given payload, with the same argument shape as EncryptDanger.
|
|
||||||
DecryptDanger(out, ad, ciphertext []byte, n uint64, nb []byte) ([]byte, error)
|
|
||||||
|
|
||||||
// Overhead returns the AEAD tag size, or 0 if the receiver is nil.
|
|
||||||
Overhead() int
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewCipherState wraps the post-handshake noise.CipherState in the per-cipher type that matches cipherFunc.
|
|
||||||
// cipherFunc must be the same cipher used to build the noise CipherSuite that produced s.
|
|
||||||
func NewCipherState(s *noise.CipherState, cipherFunc noise.CipherFunc) CipherState {
|
|
||||||
switch cipherFunc.CipherName() {
|
|
||||||
case CipherAESGCM.CipherName():
|
|
||||||
return NewCipherStateAESGCM(s)
|
|
||||||
case noise.CipherChaChaPoly.CipherName():
|
|
||||||
return NewCipherStateChaChaPoly(s)
|
|
||||||
default:
|
|
||||||
panic(fmt.Sprintf("noiseutil: unsupported cipher %q", cipherFunc.CipherName()))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,222 +0,0 @@
|
|||||||
package noiseutil
|
|
||||||
|
|
||||||
import (
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/flynn/noise"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestCipherStateAESGCMRoundtrip(t *testing.T) {
|
|
||||||
enc, dec := buildCipherStates(t, CipherAESGCM)
|
|
||||||
roundtrip(t, NewCipherStateAESGCM(enc), NewCipherStateAESGCM(dec))
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCipherStateChaChaPolyRoundtrip(t *testing.T) {
|
|
||||||
enc, dec := buildCipherStates(t, noise.CipherChaChaPoly)
|
|
||||||
roundtrip(t, NewCipherStateChaChaPoly(enc), NewCipherStateChaChaPoly(dec))
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewCipherStateDispatch(t *testing.T) {
|
|
||||||
encA, _ := buildCipherStates(t, CipherAESGCM)
|
|
||||||
encC, _ := buildCipherStates(t, noise.CipherChaChaPoly)
|
|
||||||
|
|
||||||
assert.IsType(t, &CipherStateAESGCM{}, NewCipherState(encA, CipherAESGCM))
|
|
||||||
assert.IsType(t, &CipherStateChaChaPoly{}, NewCipherState(encC, noise.CipherChaChaPoly))
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewCipherStateUnsupportedPanics(t *testing.T) {
|
|
||||||
enc, _ := buildCipherStates(t, CipherAESGCM)
|
|
||||||
assert.Panics(t, func() {
|
|
||||||
NewCipherState(enc, fakeCipher{})
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
type fakeCipher struct{}
|
|
||||||
|
|
||||||
func (fakeCipher) Cipher(k [32]byte) noise.Cipher { return nil }
|
|
||||||
func (fakeCipher) CipherName() string { return "Fake" }
|
|
||||||
|
|
||||||
// buildCipherStates runs an in-memory NN handshake with the requested cipher
|
|
||||||
// to produce a pair of post-handshake CipherStates that share keys.
|
|
||||||
func buildCipherStates(t *testing.T, c noise.CipherFunc) (*noise.CipherState, *noise.CipherState) {
|
|
||||||
t.Helper()
|
|
||||||
suite := noise.NewCipherSuite(noise.DH25519, c, noise.HashSHA256)
|
|
||||||
cfg := noise.Config{CipherSuite: suite, Pattern: noise.HandshakeNN}
|
|
||||||
cfg.Initiator = true
|
|
||||||
hsI, err := noise.NewHandshakeState(cfg)
|
|
||||||
require.NoError(t, err)
|
|
||||||
cfg.Initiator = false
|
|
||||||
hsR, err := noise.NewHandshakeState(cfg)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
msg, _, _, err := hsI.WriteMessage(nil, nil)
|
|
||||||
require.NoError(t, err)
|
|
||||||
_, _, _, err = hsR.ReadMessage(nil, msg)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
msg, dR, _, err := hsR.WriteMessage(nil, nil)
|
|
||||||
require.NoError(t, err)
|
|
||||||
_, eI, _, err := hsI.ReadMessage(nil, msg)
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.NotNil(t, eI)
|
|
||||||
require.NotNil(t, dR)
|
|
||||||
|
|
||||||
// noise returns (cs1, cs2) where cs1 is the initiator->responder cipher.
|
|
||||||
return eI, dR
|
|
||||||
}
|
|
||||||
|
|
||||||
func roundtrip(t *testing.T, enc, dec CipherState) {
|
|
||||||
t.Helper()
|
|
||||||
plaintext := []byte("nebula cipher state roundtrip")
|
|
||||||
ad := []byte("aad")
|
|
||||||
nb := make([]byte, 12)
|
|
||||||
|
|
||||||
ct, err := enc.EncryptDanger(nil, ad, plaintext, 1, nb)
|
|
||||||
require.NoError(t, err)
|
|
||||||
assert.NotEqual(t, plaintext, ct)
|
|
||||||
|
|
||||||
pt, err := dec.DecryptDanger(nil, ad, ct, 1, nb)
|
|
||||||
require.NoError(t, err)
|
|
||||||
assert.Equal(t, plaintext, pt)
|
|
||||||
|
|
||||||
// Wrong nonce must fail authentication.
|
|
||||||
_, err = dec.DecryptDanger(nil, ad, ct, 2, nb)
|
|
||||||
require.Error(t, err)
|
|
||||||
|
|
||||||
assert.Equal(t, enc.Overhead(), dec.Overhead())
|
|
||||||
assert.Equal(t, 16, enc.Overhead())
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkCipherStateEncryptAESGCM(b *testing.B) {
|
|
||||||
enc, _ := buildCipherStatesB(b, CipherAESGCM)
|
|
||||||
benchEncryptCipherState(b, NewCipherState(enc, CipherAESGCM))
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkCipherStateEncryptChaChaPoly(b *testing.B) {
|
|
||||||
enc, _ := buildCipherStatesB(b, noise.CipherChaChaPoly)
|
|
||||||
benchEncryptCipherState(b, NewCipherState(enc, noise.CipherChaChaPoly))
|
|
||||||
}
|
|
||||||
|
|
||||||
func benchEncryptCipherState(b *testing.B, cs CipherState) {
|
|
||||||
plaintext := make([]byte, 1280)
|
|
||||||
ad := make([]byte, 16)
|
|
||||||
nb := make([]byte, 12)
|
|
||||||
out := make([]byte, 0, len(plaintext)+cs.Overhead())
|
|
||||||
b.ResetTimer()
|
|
||||||
b.ReportAllocs()
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
var err error
|
|
||||||
out, err = cs.EncryptDanger(out[:0], ad, plaintext, uint64(i+1), nb)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func buildCipherStatesB(b *testing.B, c noise.CipherFunc) (*noise.CipherState, *noise.CipherState) {
|
|
||||||
b.Helper()
|
|
||||||
suite := noise.NewCipherSuite(noise.DH25519, c, noise.HashSHA256)
|
|
||||||
cfg := noise.Config{CipherSuite: suite, Pattern: noise.HandshakeNN}
|
|
||||||
cfg.Initiator = true
|
|
||||||
hsI, err := noise.NewHandshakeState(cfg)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
cfg.Initiator = false
|
|
||||||
hsR, err := noise.NewHandshakeState(cfg)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
msg, _, _, err := hsI.WriteMessage(nil, nil)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
if _, _, _, err := hsR.ReadMessage(nil, msg); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
msg, dR, _, err := hsR.WriteMessage(nil, nil)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
_, eI, _, err := hsI.ReadMessage(nil, msg)
|
|
||||||
if err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
return eI, dR
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestDecryptDangerRelayShapeNoAlloc covers the AD-only relay path used in
|
|
||||||
// outside.go's handleOutsideRelayPacket: the body is AD, the trailing 16 bytes
|
|
||||||
// are the AEAD tag, the plaintext is empty, and the caller passes nil as the
|
|
||||||
// destination because it only needs the auth side-effect. The call must
|
|
||||||
// succeed, return an empty plaintext, and not allocate on the hot path.
|
|
||||||
func TestDecryptDangerRelayShapeNoAlloc(t *testing.T) {
|
|
||||||
cases := []struct {
|
|
||||||
name string
|
|
||||||
c noise.CipherFunc
|
|
||||||
wrap func(*noise.CipherState) CipherState
|
|
||||||
}{
|
|
||||||
{"AESGCM", CipherAESGCM, func(cs *noise.CipherState) CipherState { return NewCipherStateAESGCM(cs) }},
|
|
||||||
{"ChaChaPoly", noise.CipherChaChaPoly, func(cs *noise.CipherState) CipherState { return NewCipherStateChaChaPoly(cs) }},
|
|
||||||
}
|
|
||||||
for _, tc := range cases {
|
|
||||||
t.Run(tc.name, func(t *testing.T) {
|
|
||||||
encCS, decCS := buildCipherStates(t, tc.c)
|
|
||||||
enc, dec := tc.wrap(encCS), tc.wrap(decCS)
|
|
||||||
|
|
||||||
ad := make([]byte, 1200) // typical relay packet body size
|
|
||||||
for i := range ad {
|
|
||||||
ad[i] = byte(i)
|
|
||||||
}
|
|
||||||
nb := make([]byte, 12)
|
|
||||||
|
|
||||||
// Build the "signature value" the way handleOutsideRelayPacket sees it:
|
|
||||||
// empty plaintext encrypted with the body as AD yields just the 16-byte tag.
|
|
||||||
tag, err := enc.EncryptDanger(nil, ad, nil, 1, nb)
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.Len(t, tag, dec.Overhead())
|
|
||||||
|
|
||||||
// Sanity: the relay-shaped call returns empty plaintext, no error.
|
|
||||||
out, err := dec.DecryptDanger(nil, ad, tag, 1, nb)
|
|
||||||
require.NoError(t, err)
|
|
||||||
assert.Empty(t, out)
|
|
||||||
|
|
||||||
// Tampering with the AD must fail authentication.
|
|
||||||
ad[0] ^= 0xff
|
|
||||||
_, err = dec.DecryptDanger(nil, ad, tag, 1, nb)
|
|
||||||
require.Error(t, err)
|
|
||||||
ad[0] ^= 0xff
|
|
||||||
|
|
||||||
// The hot path must not allocate. AllocsPerRun does a warm-up run, so any
|
|
||||||
// one-time setup is excluded. Counter has to advance so the AEAD nonce is
|
|
||||||
// unique per call, but we don't care whether the auth succeeds — we only
|
|
||||||
// care about whether the call path allocates.
|
|
||||||
var counter uint64 = 2
|
|
||||||
allocs := testing.AllocsPerRun(100, func() {
|
|
||||||
_, _ = dec.DecryptDanger(nil, ad, tag, counter, nb)
|
|
||||||
counter++
|
|
||||||
})
|
|
||||||
assert.Equal(t, 0.0, allocs, "DecryptDanger(nil, ...) must not allocate")
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestCipherStateNilSafety(t *testing.T) {
|
|
||||||
var aes *CipherStateAESGCM
|
|
||||||
_, err := aes.EncryptDanger(nil, nil, nil, 0, make([]byte, 12))
|
|
||||||
require.Error(t, err)
|
|
||||||
out, err := aes.DecryptDanger(nil, nil, nil, 0, make([]byte, 12))
|
|
||||||
require.NoError(t, err)
|
|
||||||
assert.Empty(t, out)
|
|
||||||
assert.Equal(t, 0, aes.Overhead())
|
|
||||||
|
|
||||||
var cc *CipherStateChaChaPoly
|
|
||||||
_, err = cc.EncryptDanger(nil, nil, nil, 0, make([]byte, 12))
|
|
||||||
require.Error(t, err)
|
|
||||||
out, err = cc.DecryptDanger(nil, nil, nil, 0, make([]byte, 12))
|
|
||||||
require.NoError(t, err)
|
|
||||||
assert.Empty(t, out)
|
|
||||||
assert.Equal(t, 0, cc.Overhead())
|
|
||||||
}
|
|
||||||
+230
-239
@@ -13,7 +13,6 @@ import (
|
|||||||
|
|
||||||
"github.com/slackhq/nebula/firewall"
|
"github.com/slackhq/nebula/firewall"
|
||||||
"github.com/slackhq/nebula/header"
|
"github.com/slackhq/nebula/header"
|
||||||
"github.com/slackhq/nebula/udp"
|
|
||||||
"golang.org/x/net/ipv4"
|
"golang.org/x/net/ipv4"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -21,46 +20,23 @@ const (
|
|||||||
minFwPacketLen = 4
|
minFwPacketLen = 4
|
||||||
)
|
)
|
||||||
|
|
||||||
var ErrOutOfWindow = errors.New("out of window packet")
|
func (f *Interface) readOutsidePackets(via ViaSender, out []byte, packet []byte, h *header.H, fwPacket *firewall.Packet, lhf *LightHouseHandler, nb []byte, q int, localCache firewall.ConntrackCache) {
|
||||||
|
|
||||||
func (f *Interface) readOutsidePackets(via ViaSender, packet []byte, h *header.H, fwPacket *firewall.Packet, lhf *LightHouseHandler, nb []byte, q int, localCache firewall.ConntrackCache, meta udp.RxMeta) {
|
|
||||||
err := h.Parse(packet)
|
err := h.Parse(packet)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// Hole punch packets are 0 or 1 byte big, so lets ignore printing those errors
|
// Hole punch packets are 0 or 1 byte big, so lets ignore printing those errors
|
||||||
// TODO: record metrics for rx holepunch/punchy packets?
|
|
||||||
if len(packet) > 1 {
|
if len(packet) > 1 {
|
||||||
f.messageMetrics.RxInvalid(1)
|
f.l.Info("Error while parsing inbound packet",
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
"from", via,
|
||||||
f.l.Debug("Error while parsing inbound packet",
|
"error", err,
|
||||||
"from", via,
|
"packet", packet,
|
||||||
"error", err,
|
)
|
||||||
"packet", packet,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if h.Version != header.Version {
|
|
||||||
f.messageMetrics.RxInvalid(1)
|
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
f.l.Debug("Unexpected header version received", "from", via)
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// Check before processing to see if this is a expected type/subtype
|
|
||||||
if !h.IsValidSubType() {
|
|
||||||
f.messageMetrics.RxInvalid(1)
|
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
f.l.Debug("Unexpected packet received", "from", via)
|
|
||||||
}
|
}
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
//l.Error("in packet ", header, packet[HeaderLen:])
|
||||||
if !via.IsRelayed {
|
if !via.IsRelayed {
|
||||||
if f.myVpnNetworksTable.Contains(via.UdpAddr.Addr()) {
|
if f.myVpnNetworksTable.Contains(via.UdpAddr.Addr()) {
|
||||||
f.messageMetrics.RxInvalid(1)
|
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
f.l.Debug("Refusing to process double encrypted packet", "from", via)
|
f.l.Debug("Refusing to process double encrypted packet", "from", via)
|
||||||
}
|
}
|
||||||
@@ -68,198 +44,229 @@ func (f *Interface) readOutsidePackets(via ViaSender, packet []byte, h *header.H
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// don't keep Rx metrics for message type, since you can see those in the tun metrics
|
|
||||||
if h.Type != header.Message {
|
|
||||||
f.messageMetrics.Rx(h.Type, h.Subtype, 1)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Unencrypted packets
|
|
||||||
switch h.Type {
|
|
||||||
case header.Handshake:
|
|
||||||
f.handshakeManager.HandleIncoming(via, packet, h)
|
|
||||||
return
|
|
||||||
|
|
||||||
case header.RecvError:
|
|
||||||
f.handleRecvError(via.UdpAddr, h)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// Relay packets are special
|
|
||||||
isMessageRelay := (h.Type == header.Message && h.Subtype == header.MessageRelay)
|
|
||||||
|
|
||||||
var hostinfo *HostInfo
|
var hostinfo *HostInfo
|
||||||
if isMessageRelay {
|
// verify if we've seen this index before, otherwise respond to the handshake initiation
|
||||||
|
if h.Type == header.Message && h.Subtype == header.MessageRelay {
|
||||||
hostinfo = f.hostMap.QueryRelayIndex(h.RemoteIndex)
|
hostinfo = f.hostMap.QueryRelayIndex(h.RemoteIndex)
|
||||||
} else {
|
} else {
|
||||||
hostinfo = f.hostMap.QueryIndex(h.RemoteIndex)
|
hostinfo = f.hostMap.QueryIndex(h.RemoteIndex)
|
||||||
}
|
}
|
||||||
|
|
||||||
// At this point we should have a valid existing tunnel, verify and send
|
var ci *ConnectionState
|
||||||
// recvError if necessary
|
if hostinfo != nil {
|
||||||
if hostinfo == nil || hostinfo.ConnectionState == nil {
|
ci = hostinfo.ConnectionState
|
||||||
if !via.IsRelayed {
|
|
||||||
f.maybeSendRecvError(via.UdpAddr, h.RemoteIndex)
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// All remaining packets are encrypted
|
|
||||||
ci := hostinfo.ConnectionState
|
|
||||||
if !ci.window.Check(f.l, h.MessageCounter) {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// Relay packets are special
|
|
||||||
if isMessageRelay {
|
|
||||||
f.handleOutsideRelayPacket(hostinfo, via, packet, h, fwPacket, lhf, nb, q, localCache, meta)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
out := f.batchers[q].Reserve(len(packet))[:0]
|
|
||||||
out, err = f.decrypt(hostinfo, h.MessageCounter, out, packet, h, nb)
|
|
||||||
if err != nil {
|
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
hostinfo.logger(f.l).Debug("Failed to decrypt packet",
|
|
||||||
"error", err,
|
|
||||||
"from", via,
|
|
||||||
"header", h,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// Roam before we respond
|
|
||||||
f.handleHostRoaming(hostinfo, via)
|
|
||||||
f.connectionManager.In(hostinfo)
|
|
||||||
|
|
||||||
switch h.Type {
|
switch h.Type {
|
||||||
case header.Message:
|
case header.Message:
|
||||||
|
if !f.handleEncrypted(ci, via, h) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
switch h.Subtype {
|
switch h.Subtype {
|
||||||
case header.MessageNone:
|
case header.MessageNone:
|
||||||
f.handleOutsideMessagePacket(hostinfo, out, packet, fwPacket, nb, q, localCache, meta)
|
if !f.decryptToTun(hostinfo, h.MessageCounter, out, packet, fwPacket, nb, q, localCache) {
|
||||||
default:
|
return
|
||||||
hostinfo.logger(f.l).Error("IsValidSubType was true, but unexpected message subtype seen", "from", via, "header", h)
|
}
|
||||||
return
|
case header.MessageRelay:
|
||||||
|
// The entire body is sent as AD, not encrypted.
|
||||||
|
// The packet consists of a 16-byte parsed Nebula header, Associated Data-protected payload, and a trailing 16-byte AEAD signature value.
|
||||||
|
// The packet is guaranteed to be at least 16 bytes at this point, b/c it got past the h.Parse() call above. If it's
|
||||||
|
// otherwise malformed (meaning, there is no trailing 16 byte AEAD value), then this will result in at worst a 0-length slice
|
||||||
|
// which will gracefully fail in the DecryptDanger call.
|
||||||
|
signedPayload := packet[:len(packet)-hostinfo.ConnectionState.dKey.Overhead()]
|
||||||
|
signatureValue := packet[len(packet)-hostinfo.ConnectionState.dKey.Overhead():]
|
||||||
|
out, err = hostinfo.ConnectionState.dKey.DecryptDanger(out, signedPayload, signatureValue, h.MessageCounter, nb)
|
||||||
|
if err != nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
// Successfully validated the thing. Get rid of the Relay header.
|
||||||
|
signedPayload = signedPayload[header.Len:]
|
||||||
|
// Pull the Roaming parts up here, and return in all call paths.
|
||||||
|
f.handleHostRoaming(hostinfo, via)
|
||||||
|
// Track usage of both the HostInfo and the Relay for the received & authenticated packet
|
||||||
|
f.connectionManager.In(hostinfo)
|
||||||
|
f.connectionManager.RelayUsed(h.RemoteIndex)
|
||||||
|
|
||||||
|
relay, ok := hostinfo.relayState.QueryRelayForByIdx(h.RemoteIndex)
|
||||||
|
if !ok {
|
||||||
|
// The only way this happens is if hostmap has an index to the correct HostInfo, but the HostInfo is missing
|
||||||
|
// its internal mapping. This should never happen.
|
||||||
|
hostinfo.logger(f.l).Error("HostInfo missing remote relay index",
|
||||||
|
"vpnAddrs", hostinfo.vpnAddrs,
|
||||||
|
"remoteIndex", h.RemoteIndex,
|
||||||
|
)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
switch relay.Type {
|
||||||
|
case TerminalType:
|
||||||
|
// If I am the target of this relay, process the unwrapped packet
|
||||||
|
// From this recursive point, all these variables are 'burned'. We shouldn't rely on them again.
|
||||||
|
via = ViaSender{
|
||||||
|
UdpAddr: via.UdpAddr,
|
||||||
|
relayHI: hostinfo,
|
||||||
|
remoteIdx: relay.RemoteIndex,
|
||||||
|
relay: relay,
|
||||||
|
IsRelayed: true,
|
||||||
|
}
|
||||||
|
f.readOutsidePackets(via, out[:0], signedPayload, h, fwPacket, lhf, nb, q, localCache)
|
||||||
|
return
|
||||||
|
case ForwardingType:
|
||||||
|
// Find the target HostInfo relay object
|
||||||
|
targetHI, targetRelay, err := f.hostMap.QueryVpnAddrsRelayFor(hostinfo.vpnAddrs, relay.PeerAddr)
|
||||||
|
if err != nil {
|
||||||
|
hostinfo.logger(f.l).Info("Failed to find target host info by ip",
|
||||||
|
"relayTo", relay.PeerAddr,
|
||||||
|
"error", err,
|
||||||
|
"hostinfo.vpnAddrs", hostinfo.vpnAddrs,
|
||||||
|
)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// If that relay is Established, forward the payload through it
|
||||||
|
if targetRelay.State == Established {
|
||||||
|
switch targetRelay.Type {
|
||||||
|
case ForwardingType:
|
||||||
|
// Forward this packet through the relay tunnel
|
||||||
|
// Find the target HostInfo
|
||||||
|
f.SendVia(targetHI, targetRelay, signedPayload, nb, out, false)
|
||||||
|
return
|
||||||
|
case TerminalType:
|
||||||
|
hostinfo.logger(f.l).Error("Unexpected Relay Type of Terminal")
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
hostinfo.logger(f.l).Info("Unexpected target relay state",
|
||||||
|
"relayTo", relay.PeerAddr,
|
||||||
|
"relayFrom", hostinfo.vpnAddrs[0],
|
||||||
|
"targetRelayState", targetRelay.State,
|
||||||
|
)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
case header.LightHouse:
|
case header.LightHouse:
|
||||||
|
f.messageMetrics.Rx(h.Type, h.Subtype, 1)
|
||||||
|
if !f.handleEncrypted(ci, via, h) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
d, err := f.decrypt(hostinfo, h.MessageCounter, out, packet, h, nb)
|
||||||
|
if err != nil {
|
||||||
|
hostinfo.logger(f.l).Error("Failed to decrypt lighthouse packet",
|
||||||
|
"error", err,
|
||||||
|
"from", via,
|
||||||
|
"packet", packet,
|
||||||
|
)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
//TODO: assert via is not relayed
|
//TODO: assert via is not relayed
|
||||||
lhf.HandleRequest(via.UdpAddr, hostinfo.vpnAddrs, out, f)
|
lhf.HandleRequest(via.UdpAddr, hostinfo.vpnAddrs, d, f)
|
||||||
|
|
||||||
|
// Fallthrough to the bottom to record incoming traffic
|
||||||
|
|
||||||
case header.Test:
|
case header.Test:
|
||||||
switch h.Subtype {
|
f.messageMetrics.Rx(h.Type, h.Subtype, 1)
|
||||||
case header.TestReply:
|
if !f.handleEncrypted(ci, via, h) {
|
||||||
// No-op, useful for the Roaming and connectionManager side-effects above
|
|
||||||
case header.TestRequest:
|
|
||||||
f.send(header.Test, header.TestReply, ci, hostinfo, out, nb, out)
|
|
||||||
default:
|
|
||||||
hostinfo.logger(f.l).Error("IsValidSubType was true, but unexpected test subtype seen", "from", via, "header", h)
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
d, err := f.decrypt(hostinfo, h.MessageCounter, out, packet, h, nb)
|
||||||
|
if err != nil {
|
||||||
|
hostinfo.logger(f.l).Error("Failed to decrypt test packet",
|
||||||
|
"error", err,
|
||||||
|
"from", via,
|
||||||
|
"packet", packet,
|
||||||
|
)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
switch h.Subtype {
|
||||||
|
case header.TestRequest:
|
||||||
|
// This testRequest might be from TryPromoteBest, so we should roam
|
||||||
|
// to the new IP address before responding
|
||||||
|
f.handleHostRoaming(hostinfo, via)
|
||||||
|
f.send(header.Test, header.TestReply, ci, hostinfo, d, nb, out)
|
||||||
|
case header.MTUDProbeRequest:
|
||||||
|
// Reply with just the 8-byte ack header so the reverse path doesn't have to
|
||||||
|
// carry the full probe size; we only verify the forward direction.
|
||||||
|
if len(d) >= 8 {
|
||||||
|
f.send(header.Test, header.MTUDProbeReply, ci, hostinfo, d[:8], nb, out)
|
||||||
|
}
|
||||||
|
case header.MTUDProbeReply:
|
||||||
|
f.pmtudManager.HandleReply(hostinfo.localIndexId, d)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Fallthrough to the bottom to record incoming traffic
|
||||||
|
|
||||||
|
// Non encrypted messages below here, they should not fall through to avoid tracking incoming traffic since they
|
||||||
|
// are unauthenticated
|
||||||
|
|
||||||
|
case header.Handshake:
|
||||||
|
f.messageMetrics.Rx(h.Type, h.Subtype, 1)
|
||||||
|
f.handshakeManager.HandleIncoming(via, packet, h)
|
||||||
|
return
|
||||||
|
|
||||||
|
case header.RecvError:
|
||||||
|
f.messageMetrics.Rx(h.Type, h.Subtype, 1)
|
||||||
|
f.handleRecvError(via.UdpAddr, h)
|
||||||
|
return
|
||||||
|
|
||||||
case header.CloseTunnel:
|
case header.CloseTunnel:
|
||||||
|
f.messageMetrics.Rx(h.Type, h.Subtype, 1)
|
||||||
|
if !f.handleEncrypted(ci, via, h) {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
_, err = f.decrypt(hostinfo, h.MessageCounter, out, packet, h, nb)
|
||||||
|
if err != nil {
|
||||||
|
hostinfo.logger(f.l).Error("Failed to decrypt CloseTunnel packet",
|
||||||
|
"error", err,
|
||||||
|
"from", via,
|
||||||
|
"packet", packet,
|
||||||
|
)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
hostinfo.logger(f.l).Info("Close tunnel received, tearing down.", "from", via)
|
hostinfo.logger(f.l).Info("Close tunnel received, tearing down.", "from", via)
|
||||||
|
|
||||||
f.closeTunnel(hostinfo)
|
f.closeTunnel(hostinfo)
|
||||||
|
return
|
||||||
|
|
||||||
case header.Control:
|
case header.Control:
|
||||||
f.relayManager.HandleControlMsg(hostinfo, out, f)
|
if !f.handleEncrypted(ci, via, h) {
|
||||||
|
return
|
||||||
default:
|
|
||||||
hostinfo.logger(f.l).Error("IsValidSubType was true, but unexpected message type seen", "from", via, "header", h)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (f *Interface) handleOutsideRelayPacket(hostinfo *HostInfo, via ViaSender, packet []byte, h *header.H, fwPacket *firewall.Packet, lhf *LightHouseHandler, nb []byte, q int, localCache firewall.ConntrackCache, meta udp.RxMeta) {
|
|
||||||
// The entire body is sent as AD, not encrypted.
|
|
||||||
// The packet consists of a 16-byte parsed Nebula header, Associated Data-protected payload, and a trailing 16-byte AEAD signature value.
|
|
||||||
// The packet is guaranteed to be at least 16 bytes at this point, b/c it got past the h.Parse() call above. If it's
|
|
||||||
// otherwise malformed (meaning, there is no trailing 16 byte AEAD value), then this will result in at worst a 0-length slice
|
|
||||||
// which will gracefully fail in the DecryptDanger call.
|
|
||||||
signedPayload := packet[:len(packet)-hostinfo.ConnectionState.dKey.Overhead()]
|
|
||||||
signatureValue := packet[len(packet)-hostinfo.ConnectionState.dKey.Overhead():]
|
|
||||||
// The decrypted output is empty (relay packets carry their payload as AD) and unused.
|
|
||||||
// The recursive readOutsidePackets call below operates on signedPayload. Passing
|
|
||||||
// nil avoids reserving an arena slot.
|
|
||||||
if _, err := hostinfo.ConnectionState.dKey.DecryptDanger(nil, signedPayload, signatureValue, h.MessageCounter, nb); err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
// Successfully validated the thing. Get rid of the Relay header.
|
|
||||||
signedPayload = signedPayload[header.Len:]
|
|
||||||
// Pull the Roaming parts up here, and return in all call paths.
|
|
||||||
f.handleHostRoaming(hostinfo, via)
|
|
||||||
// Track usage of both the HostInfo and the Relay for the received & authenticated packet
|
|
||||||
f.connectionManager.In(hostinfo)
|
|
||||||
f.connectionManager.RelayUsed(h.RemoteIndex)
|
|
||||||
|
|
||||||
relay, ok := hostinfo.relayState.QueryRelayForByIdx(h.RemoteIndex)
|
|
||||||
if !ok {
|
|
||||||
// The only way this happens is if hostmap has an index to the correct HostInfo, but the HostInfo is missing
|
|
||||||
// its internal mapping. This should never happen.
|
|
||||||
hostinfo.logger(f.l).Error("HostInfo missing remote relay index",
|
|
||||||
"vpnAddrs", hostinfo.vpnAddrs,
|
|
||||||
"remoteIndex", h.RemoteIndex,
|
|
||||||
)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
switch relay.Type {
|
|
||||||
case TerminalType:
|
|
||||||
// If I am the target of this relay, process the unwrapped packet
|
|
||||||
// From this recursive point, all these variables are 'burned'. We shouldn't rely on them again.
|
|
||||||
via = ViaSender{
|
|
||||||
UdpAddr: via.UdpAddr,
|
|
||||||
relayHI: hostinfo,
|
|
||||||
remoteIdx: relay.RemoteIndex,
|
|
||||||
relay: relay,
|
|
||||||
IsRelayed: true,
|
|
||||||
}
|
}
|
||||||
f.readOutsidePackets(via, signedPayload, h, fwPacket, lhf, nb, q, localCache, meta)
|
|
||||||
case ForwardingType:
|
d, err := f.decrypt(hostinfo, h.MessageCounter, out, packet, h, nb)
|
||||||
// Find the target HostInfo relay object
|
|
||||||
targetHI, targetRelay, err := f.hostMap.QueryVpnAddrsRelayFor(hostinfo.vpnAddrs, relay.PeerAddr)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
hostinfo.logger(f.l).Info("Failed to find target host info by ip",
|
hostinfo.logger(f.l).Error("Failed to decrypt Control packet",
|
||||||
"relayTo", relay.PeerAddr,
|
|
||||||
"error", err,
|
"error", err,
|
||||||
"hostinfo.vpnAddrs", hostinfo.vpnAddrs,
|
"from", via,
|
||||||
|
"packet", packet,
|
||||||
)
|
)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// If that relay is Established, forward the payload through it
|
f.relayManager.HandleControlMsg(hostinfo, d, f)
|
||||||
if targetRelay.State == Established {
|
|
||||||
switch targetRelay.Type {
|
|
||||||
case ForwardingType:
|
|
||||||
// Forward this packet through the relay tunnel
|
|
||||||
// Find the target HostInfo //todo it would potentially be nice to batch these
|
|
||||||
out := f.batchers[q].Reserve(len(packet) + header.Len + hostinfo.ConnectionState.dKey.Overhead())[:0]
|
|
||||||
f.SendVia(targetHI, targetRelay, signedPayload, nb, out, false)
|
|
||||||
case TerminalType:
|
|
||||||
hostinfo.logger(f.l).Error("Unexpected Relay Type of Terminal")
|
|
||||||
return
|
|
||||||
default:
|
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
hostinfo.logger(f.l).Debug("Unexpected targetRelay Type", "from", via, "relayType", targetRelay.Type)
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
hostinfo.logger(f.l).Info("Unexpected target relay state",
|
|
||||||
"relayTo", relay.PeerAddr,
|
|
||||||
"relayFrom", hostinfo.vpnAddrs[0],
|
|
||||||
"targetRelayState", targetRelay.State,
|
|
||||||
)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
default:
|
default:
|
||||||
|
f.messageMetrics.Rx(h.Type, h.Subtype, 1)
|
||||||
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
hostinfo.logger(f.l).Debug("Unexpected relay type", "from", via, "relayType", relay.Type)
|
hostinfo.logger(f.l).Debug("Unexpected packet received", "from", via)
|
||||||
}
|
}
|
||||||
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
f.handleHostRoaming(hostinfo, via)
|
||||||
|
|
||||||
|
f.connectionManager.In(hostinfo)
|
||||||
}
|
}
|
||||||
|
|
||||||
// closeTunnel closes a tunnel locally, it does not send a closeTunnel packet to the remote
|
// closeTunnel closes a tunnel locally, it does not send a closeTunnel packet to the remote
|
||||||
func (f *Interface) closeTunnel(hostInfo *HostInfo) {
|
func (f *Interface) closeTunnel(hostInfo *HostInfo) {
|
||||||
|
f.pmtudManager.OnTunnelDown(hostInfo)
|
||||||
final := f.hostMap.DeleteHostInfo(hostInfo)
|
final := f.hostMap.DeleteHostInfo(hostInfo)
|
||||||
if final {
|
if final {
|
||||||
// We no longer have any tunnels with this vpn addr, clear learned lighthouse state to lower memory usage
|
// We no longer have any tunnels with this vpn addr, clear learned lighthouse state to lower memory usage
|
||||||
@@ -299,10 +306,28 @@ func (f *Interface) handleHostRoaming(hostinfo *HostInfo, via ViaSender) {
|
|||||||
hostinfo.lastRoam = time.Now()
|
hostinfo.lastRoam = time.Now()
|
||||||
hostinfo.lastRoamRemote = hostinfo.remote
|
hostinfo.lastRoamRemote = hostinfo.remote
|
||||||
hostinfo.SetRemote(via.UdpAddr)
|
hostinfo.SetRemote(via.UdpAddr)
|
||||||
|
f.pmtudManager.OnRoam(hostinfo)
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// handleEncrypted returns true if a packet should be processed, false otherwise
|
||||||
|
func (f *Interface) handleEncrypted(ci *ConnectionState, via ViaSender, h *header.H) bool {
|
||||||
|
// If connectionstate does not exist, send a recv error, if possible, to encourage a fast reconnect
|
||||||
|
if ci == nil {
|
||||||
|
if !via.IsRelayed {
|
||||||
|
f.maybeSendRecvError(via.UdpAddr, h.RemoteIndex)
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
// If the window check fails, refuse to process the packet, but don't send a recv error
|
||||||
|
if !ci.window.Check(f.l, h.MessageCounter) {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
var (
|
var (
|
||||||
ErrPacketTooShort = errors.New("packet is too short")
|
ErrPacketTooShort = errors.New("packet is too short")
|
||||||
ErrUnknownIPVersion = errors.New("packet is an unknown ip version")
|
ErrUnknownIPVersion = errors.New("packet is an unknown ip version")
|
||||||
@@ -509,74 +534,38 @@ func (f *Interface) decrypt(hostinfo *HostInfo, mc uint64, out []byte, packet []
|
|||||||
}
|
}
|
||||||
|
|
||||||
if !hostinfo.ConnectionState.window.Update(f.l, mc) {
|
if !hostinfo.ConnectionState.window.Update(f.l, mc) {
|
||||||
return nil, ErrOutOfWindow
|
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
|
hostinfo.logger(f.l).Debug("dropping out of window packet", "header", h)
|
||||||
|
}
|
||||||
|
return nil, errors.New("out of window packet")
|
||||||
}
|
}
|
||||||
|
|
||||||
return out, nil
|
return out, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// 2-bit IP-level ECN codepoints (lower bits of IPv4 ToS / IPv6 TC).
|
func (f *Interface) decryptToTun(hostinfo *HostInfo, messageCounter uint64, out []byte, packet []byte, fwPacket *firewall.Packet, nb []byte, q int, localCache firewall.ConntrackCache) bool {
|
||||||
const (
|
var err error
|
||||||
ecnNotECT = 0x00
|
|
||||||
ecnECT1 = 0x01
|
|
||||||
ecnECT0 = 0x02
|
|
||||||
ecnCE = 0x03
|
|
||||||
)
|
|
||||||
|
|
||||||
// applyOuterECN folds an outer CE mark from the underlay into the inner
|
out, err = hostinfo.ConnectionState.dKey.DecryptDanger(out, packet[:header.Len], packet[header.Len:], messageCounter, nb)
|
||||||
// IP header per RFC 6040 normal mode. It mutates pkt[1] in place. Other
|
if err != nil {
|
||||||
// codepoints are advisory only and leave the inner unchanged.
|
hostinfo.logger(f.l).Error("Failed to decrypt packet", "error", err)
|
||||||
//
|
return false
|
||||||
// Merge cases (outer × inner → action):
|
|
||||||
//
|
|
||||||
// outer != CE : no-op (inner is authoritative)
|
|
||||||
// outer == CE, inner Not-ECT : log; cannot propagate to a non-ECN host
|
|
||||||
// outer == CE, inner ECT/CE : rewrite inner ECN to CE
|
|
||||||
func applyOuterECN(pkt []byte, outerECN byte, hostinfo *HostInfo, l *slog.Logger) {
|
|
||||||
if outerECN&ecnCE != ecnCE || len(pkt) < 2 {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
switch pkt[0] >> 4 {
|
|
||||||
case 4:
|
|
||||||
switch pkt[1] & 0x03 {
|
|
||||||
case ecnNotECT:
|
|
||||||
if l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
hostinfo.logger(l).Debug("RFC 6040: outer CE on inner Not-ECT, leaving inner unchanged")
|
|
||||||
}
|
|
||||||
case ecnCE:
|
|
||||||
// Already CE.
|
|
||||||
default:
|
|
||||||
pkt[1] = (pkt[1] &^ 0x03) | ecnCE
|
|
||||||
}
|
|
||||||
case 6:
|
|
||||||
switch (pkt[1] >> 4) & 0x03 {
|
|
||||||
case ecnNotECT:
|
|
||||||
if l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
hostinfo.logger(l).Debug("RFC 6040: outer CE on inner Not-ECT, leaving inner unchanged")
|
|
||||||
}
|
|
||||||
case ecnCE:
|
|
||||||
// Already CE.
|
|
||||||
default:
|
|
||||||
pkt[1] = (pkt[1] &^ 0x30) | (ecnCE << 4)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (f *Interface) handleOutsideMessagePacket(hostinfo *HostInfo, out []byte, packet []byte, fwPacket *firewall.Packet, nb []byte, q int, localCache firewall.ConntrackCache, meta udp.RxMeta) {
|
|
||||||
// RFC 6040 normal-mode combine: fold any outer CE mark stamped by the
|
|
||||||
// underlay into the inner header before firewall + TUN write. Other
|
|
||||||
// outer codepoints are advisory only — we keep the inner unchanged.
|
|
||||||
if f.ecnEnabled.Load() {
|
|
||||||
applyOuterECN(out, meta.OuterECN, hostinfo, f.l)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
err := newPacket(out, true, fwPacket)
|
err = newPacket(out, true, fwPacket)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
hostinfo.logger(f.l).Warn("Error while validating inbound packet",
|
hostinfo.logger(f.l).Warn("Error while validating inbound packet",
|
||||||
"error", err,
|
"error", err,
|
||||||
"packet", out,
|
"packet", out,
|
||||||
)
|
)
|
||||||
return
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
if !hostinfo.ConnectionState.window.Update(f.l, messageCounter) {
|
||||||
|
if f.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
|
hostinfo.logger(f.l).Debug("dropping out of window packet", "fwPacket", fwPacket)
|
||||||
|
}
|
||||||
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
dropReason := f.firewall.Drop(*fwPacket, true, hostinfo, f.pki.GetCAPool(), localCache)
|
dropReason := f.firewall.Drop(*fwPacket, true, hostinfo, f.pki.GetCAPool(), localCache)
|
||||||
@@ -590,13 +579,15 @@ func (f *Interface) handleOutsideMessagePacket(hostinfo *HostInfo, out []byte, p
|
|||||||
"reason", dropReason,
|
"reason", dropReason,
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
return
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
err = f.batchers[q].Commit(out)
|
f.connectionManager.In(hostinfo)
|
||||||
|
_, err = f.readers[q].Write(out)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
f.l.Error("Failed to write to tun", "error", err)
|
f.l.Error("Failed to write to tun", "error", err)
|
||||||
}
|
}
|
||||||
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *Interface) maybeSendRecvError(endpoint netip.AddrPort, index uint32) {
|
func (f *Interface) maybeSendRecvError(endpoint netip.AddrPort, index uint32) {
|
||||||
|
|||||||
@@ -1,149 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"encoding/binary"
|
|
||||||
)
|
|
||||||
|
|
||||||
// flowKey identifies a transport flow by {src, dst, sport, dport, family}.
|
|
||||||
// Comparable, so map lookups and linear scans over the slot list stay tight.
|
|
||||||
// Shared by the TCP and UDP coalescers; each coalescer keeps its own
|
|
||||||
// openSlots map, so a TCP and UDP flow on the same 5-tuple-without-proto
|
|
||||||
// never alias.
|
|
||||||
type flowKey struct {
|
|
||||||
src, dst [16]byte
|
|
||||||
sport, dport uint16
|
|
||||||
isV6 bool
|
|
||||||
}
|
|
||||||
|
|
||||||
// initialSlots is the starting capacity of the slot pool. One flow per
|
|
||||||
// packet is the worst case so this matches a typical carrier-side
|
|
||||||
// recvmmsg batch on the encrypted UDP socket.
|
|
||||||
const initialSlots = 64
|
|
||||||
|
|
||||||
// parsedIP is the IP-level result of parseIPPrologue. The caller layers
|
|
||||||
// L4-specific parsing (TCP / UDP) on top.
|
|
||||||
type parsedIP struct {
|
|
||||||
fk flowKey
|
|
||||||
ipHdrLen int
|
|
||||||
// pkt is the original buffer trimmed to the IP-declared total length.
|
|
||||||
// Anything below the IP layer (transport parsers) should slice into
|
|
||||||
// pkt rather than the unbounded original.
|
|
||||||
pkt []byte
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseIPPrologue extracts the IP-level fields the coalescers care about:
|
|
||||||
// IHL/payload length, version, src/dst addresses, and the L4 protocol byte.
|
|
||||||
// Returns ok=false for malformed input, IPv4 with options or fragmentation,
|
|
||||||
// or IPv6 with extension headers (all rejected by both coalescers in
|
|
||||||
// identical ways before this refactor).
|
|
||||||
//
|
|
||||||
// On success, p.pkt is len-trimmed to the IP-declared length so callers
|
|
||||||
// don't have to repeat the trim. wantProto is the IANA protocol number to
|
|
||||||
// require (6 for TCP, 17 for UDP); ok=false for any other value.
|
|
||||||
func parseIPPrologue(pkt []byte, wantProto byte) (parsedIP, bool) {
|
|
||||||
var p parsedIP
|
|
||||||
if len(pkt) < 20 {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
v := pkt[0] >> 4
|
|
||||||
switch v {
|
|
||||||
case 4:
|
|
||||||
ihl := int(pkt[0]&0x0f) * 4
|
|
||||||
if ihl != 20 {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
if pkt[9] != wantProto {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
// Reject actual fragmentation (MF or non-zero frag offset).
|
|
||||||
if binary.BigEndian.Uint16(pkt[6:8])&0x3fff != 0 {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
totalLen := int(binary.BigEndian.Uint16(pkt[2:4]))
|
|
||||||
if totalLen > len(pkt) || totalLen < ihl {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
p.ipHdrLen = 20
|
|
||||||
p.fk.isV6 = false
|
|
||||||
copy(p.fk.src[:4], pkt[12:16])
|
|
||||||
copy(p.fk.dst[:4], pkt[16:20])
|
|
||||||
p.pkt = pkt[:totalLen]
|
|
||||||
case 6:
|
|
||||||
if len(pkt) < 40 {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
if pkt[6] != wantProto {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
payloadLen := int(binary.BigEndian.Uint16(pkt[4:6]))
|
|
||||||
if 40+payloadLen > len(pkt) {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
p.ipHdrLen = 40
|
|
||||||
p.fk.isV6 = true
|
|
||||||
copy(p.fk.src[:], pkt[8:24])
|
|
||||||
copy(p.fk.dst[:], pkt[24:40])
|
|
||||||
p.pkt = pkt[:40+payloadLen]
|
|
||||||
default:
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
return p, true
|
|
||||||
}
|
|
||||||
|
|
||||||
// ipHeadersMatch compares the IP portion of two packet header prefixes for
|
|
||||||
// byte-for-byte equality on every field that must be identical across
|
|
||||||
// coalesced segments. Size/IPID/IPCsum and the 2-bit IP-level ECN field are
|
|
||||||
// masked out — the appendPayload step merges CE into the seed.
|
|
||||||
//
|
|
||||||
// The transport (L4) portion of the header is checked separately by the
|
|
||||||
// per-protocol matcher.
|
|
||||||
func ipHeadersMatch(a, b []byte, isV6 bool) bool {
|
|
||||||
if isV6 {
|
|
||||||
// IPv6: byte 0 = version/TC[7:4], byte 1 = TC[3:0]/flow[19:16],
|
|
||||||
// bytes [2:4] = flow[15:0], [6:8] = next_hdr/hop, [8:40] = src+dst.
|
|
||||||
// ECN lives in TC[1:0] = byte 1 mask 0x30. Skip [4:6] payload_len.
|
|
||||||
if a[0] != b[0] {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if a[1]&^0x30 != b[1]&^0x30 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !bytes.Equal(a[2:4], b[2:4]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !bytes.Equal(a[6:40], b[6:40]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
// IPv4: byte 0 = version/IHL, byte 1 = DSCP(6)|ECN(2),
|
|
||||||
// [6:10] flags/fragoff/TTL/proto, [12:20] src+dst.
|
|
||||||
// Skip [2:4] total len, [4:6] id, [10:12] csum.
|
|
||||||
if a[0] != b[0] {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if a[1]&^0x03 != b[1]&^0x03 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !bytes.Equal(a[6:10], b[6:10]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !bytes.Equal(a[12:20], b[12:20]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
// mergeECNIntoSeed ORs the 2-bit IP-level ECN field of pkt's IP header
|
|
||||||
// onto the seed's IP header, so a CE mark on any coalesced segment
|
|
||||||
// propagates to the final superpacket. (CE is 0b11; ORing yields CE if
|
|
||||||
// any segment carried it.) Used by both TCP and UDP coalescers, so the
|
|
||||||
// invariant lives in one place.
|
|
||||||
func mergeECNIntoSeed(seedHdr, pktHdr []byte, isV6 bool) {
|
|
||||||
if isV6 {
|
|
||||||
seedHdr[1] |= pktHdr[1] & 0x30
|
|
||||||
} else {
|
|
||||||
seedHdr[1] |= pktHdr[1] & 0x03
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,136 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"log/slog"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
)
|
|
||||||
|
|
||||||
// MultiCoalescer fans plaintext packets out to lane-specific batchers based
|
|
||||||
// on the IP/L4 protocol of the packet, sharing a single Reserve arena
|
|
||||||
// across lanes so the caller's allocation pattern is unchanged.
|
|
||||||
//
|
|
||||||
// Lanes are processed independently: the TCP coalescer only sees TCP, the
|
|
||||||
// UDP coalescer only sees UDP, and the passthrough lane handles everything
|
|
||||||
// else. Per-flow arrival order is preserved because a single 5-tuple only
|
|
||||||
// ever lands in one lane and each lane preserves its own slot order.
|
|
||||||
//
|
|
||||||
// Cross-lane order is NOT preserved across the TCP/UDP/passthrough split.
|
|
||||||
// This is acceptable because the carrier-side recvmmsg path already
|
|
||||||
// stable-sorts by (peer, message counter) before delivering plaintext
|
|
||||||
// here, so replay-window invariants are unaffected, and apps observe
|
|
||||||
// correct per-flow ordering — which is all the IP layer guarantees anyway.
|
|
||||||
// Do not "fix" this by interleaving lane outputs at flush time; that
|
|
||||||
// negates the entire point of coalescing (each lane needs to see runs of
|
|
||||||
// adjacent same-flow packets to coalesce them).
|
|
||||||
type MultiCoalescer struct {
|
|
||||||
tcp *TCPCoalescer
|
|
||||||
udp *UDPCoalescer
|
|
||||||
pt *Passthrough
|
|
||||||
|
|
||||||
// arena is shared across every lane (constructor hands the same
|
|
||||||
// *Arena to TCP, UDP, and Passthrough), so there's exactly one
|
|
||||||
// backing slab per MultiCoalescer instance. Each lane's Flush calls
|
|
||||||
// Reset; the resets are idempotent because Multi.Flush drains lanes
|
|
||||||
// sequentially and never Reserves in between, so a later lane's
|
|
||||||
// slots stay readable across an earlier lane's Reset (the underlying
|
|
||||||
// bytes are still alive — Reset only re-slices len to 0).
|
|
||||||
arena *util.Arena
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewMultiCoalescer builds a multi-lane batcher. tcpEnabled lets the caller
|
|
||||||
// opt out of TCP coalescing (e.g. when the queue can't do TSO); udpEnabled
|
|
||||||
// likewise gates UDP coalescing (only enable when USO was negotiated).
|
|
||||||
// Either lane disabled redirects its traffic into the passthrough lane.
|
|
||||||
// arena is the single backing slab shared across every lane; the caller
|
|
||||||
// pre-sizes it via NewArena so the hot path never allocates.
|
|
||||||
func NewMultiCoalescer(w tio.Queue, l *slog.Logger, arena *util.Arena, tcpEnabled, udpEnabled bool) *MultiCoalescer {
|
|
||||||
m := &MultiCoalescer{
|
|
||||||
pt: NewPassthrough(w, initialSlots, arena),
|
|
||||||
arena: arena,
|
|
||||||
}
|
|
||||||
if tcpEnabled {
|
|
||||||
m.tcp = NewTCPCoalescer(w, l, arena)
|
|
||||||
}
|
|
||||||
if udpEnabled {
|
|
||||||
m.udp = NewUDPCoalescer(w, arena)
|
|
||||||
}
|
|
||||||
return m
|
|
||||||
}
|
|
||||||
|
|
||||||
func (m *MultiCoalescer) Reserve(sz int) []byte {
|
|
||||||
return m.arena.Reserve(sz)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Commit dispatches pkt to the appropriate lane based on IP version + L4
|
|
||||||
// proto. Borrowed slice contract is identical to the single-lane batchers,
|
|
||||||
// pkt must remain valid until the next Flush.
|
|
||||||
//
|
|
||||||
// On the success path the IP/TCP-or-UDP parse happens here once and the
|
|
||||||
// parsed struct is handed to the lane via commitParsed so the lane doesn't
|
|
||||||
// re-walk the header.
|
|
||||||
func (m *MultiCoalescer) Commit(pkt []byte) error {
|
|
||||||
if len(pkt) < 20 {
|
|
||||||
return m.pt.Commit(pkt)
|
|
||||||
}
|
|
||||||
v := pkt[0] >> 4
|
|
||||||
var proto byte
|
|
||||||
switch v {
|
|
||||||
case 4:
|
|
||||||
proto = pkt[9]
|
|
||||||
case 6:
|
|
||||||
if len(pkt) < 40 {
|
|
||||||
return m.pt.Commit(pkt)
|
|
||||||
}
|
|
||||||
proto = pkt[6]
|
|
||||||
default:
|
|
||||||
return m.pt.Commit(pkt)
|
|
||||||
}
|
|
||||||
switch proto {
|
|
||||||
case ipProtoTCP:
|
|
||||||
if m.tcp != nil {
|
|
||||||
info, ok := parseTCPBase(pkt)
|
|
||||||
if !ok {
|
|
||||||
// Malformed/unsupported TCP shape (IP options, fragments, ...).
|
|
||||||
// Handle this via passthrough support in the TCP coalescer, to attempt to preserve flow order.
|
|
||||||
m.tcp.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
return m.tcp.commitParsed(pkt, info)
|
|
||||||
}
|
|
||||||
case ipProtoUDP:
|
|
||||||
if m.udp != nil {
|
|
||||||
info, ok := parseUDP(pkt)
|
|
||||||
if !ok {
|
|
||||||
m.udp.addPassthrough(pkt) //we could also m.pt.Commit() here I guess?
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
return m.udp.commitParsed(pkt, info)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return m.pt.Commit(pkt)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Flush drains every lane in a fixed order: TCP, UDP, passthrough. Errors
|
|
||||||
// from a lane do not stop subsequent lanes from flushing, we keep
|
|
||||||
// draining and return the first observed error so a single bad packet
|
|
||||||
// doesn't strand the others.
|
|
||||||
func (m *MultiCoalescer) Flush() error {
|
|
||||||
var errs []error
|
|
||||||
if m.tcp != nil {
|
|
||||||
if err := m.tcp.Flush(); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if m.udp != nil {
|
|
||||||
if err := m.udp.Flush(); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err := m.pt.Flush(); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
return errors.Join(errs...)
|
|
||||||
}
|
|
||||||
@@ -1,97 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/test"
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
)
|
|
||||||
|
|
||||||
// TestMultiCoalescerRoutesByProto confirms TCP/UDP/other land in the right
|
|
||||||
// lane: TCP and UDP get coalesced when their lanes are enabled, anything
|
|
||||||
// else (ICMP here) falls through to plain Write.
|
|
||||||
func TestMultiCoalescerRoutesByProto(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
m := NewMultiCoalescer(w, test.NewLogger(), util.NewArena(0), true, true)
|
|
||||||
|
|
||||||
tcpPay := make([]byte, 1200)
|
|
||||||
udpPay := make([]byte, 1200)
|
|
||||||
icmp := make([]byte, 28)
|
|
||||||
icmp[0] = 0x45
|
|
||||||
icmp[2] = 0
|
|
||||||
icmp[3] = 28
|
|
||||||
icmp[9] = 1
|
|
||||||
|
|
||||||
if err := m.Commit(buildTCPv4(1000, tcpAck, tcpPay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Commit(buildTCPv4(2200, tcpAck, tcpPay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Commit(buildUDPv4(2000, 53, udpPay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Commit(buildUDPv4(2000, 53, udpPay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Commit(icmp); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
// 1 TCP super (2 segments) + 1 UDP super (2 segments) = 2 gso writes.
|
|
||||||
if len(w.gsoWrites) != 2 {
|
|
||||||
t.Fatalf("want 2 gso writes (one TCP + one UDP), got %d", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
if len(w.writes) != 1 {
|
|
||||||
t.Fatalf("want 1 plain write (ICMP), got %d", len(w.writes))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestMultiCoalescerDisabledUDPFallsThrough verifies that when the UDP lane
|
|
||||||
// is disabled (e.g. kernel doesn't support USO), UDP packets still reach
|
|
||||||
// the kernel via the passthrough lane rather than being lost.
|
|
||||||
func TestMultiCoalescerDisabledUDPFallsThrough(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
m := NewMultiCoalescer(w, test.NewLogger(), util.NewArena(0), true, false) // TSO on, USO off
|
|
||||||
|
|
||||||
if err := m.Commit(buildUDPv4(1000, 53, make([]byte, 800))); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Commit(buildUDPv4(1000, 53, make([]byte, 800))); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 0 {
|
|
||||||
t.Errorf("UDP must NOT be coalesced when USO disabled, got %d gso writes", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
if len(w.writes) != 2 {
|
|
||||||
t.Errorf("UDP must pass through as 2 plain writes, got %d", len(w.writes))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestMultiCoalescerDisabledTCPFallsThrough mirrors the TSO=off case.
|
|
||||||
func TestMultiCoalescerDisabledTCPFallsThrough(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
m := NewMultiCoalescer(w, test.NewLogger(), util.NewArena(0), false, true) // TSO off, USO on
|
|
||||||
|
|
||||||
pay := make([]byte, 1200)
|
|
||||||
if err := m.Commit(buildTCPv4(1000, tcpAck, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Commit(buildTCPv4(2200, tcpAck, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := m.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 0 {
|
|
||||||
t.Errorf("TCP must NOT be coalesced when TSO disabled, got %d gso writes", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
if len(w.writes) != 2 {
|
|
||||||
t.Errorf("TCP must pass through as 2 plain writes, got %d", len(w.writes))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,47 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Passthrough is a RxBatcher that doesn't batch anything, it just accumulates and then sends packets.
|
|
||||||
type Passthrough struct {
|
|
||||||
out io.Writer
|
|
||||||
slots [][]byte
|
|
||||||
// arena is injected; see TCPCoalescer.arena for the contract.
|
|
||||||
arena *util.Arena
|
|
||||||
cursor int
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewPassthrough(w io.Writer, slots int, arena *util.Arena) *Passthrough {
|
|
||||||
return &Passthrough{
|
|
||||||
out: w,
|
|
||||||
slots: make([][]byte, 0, slots),
|
|
||||||
arena: arena,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (p *Passthrough) Reserve(sz int) []byte {
|
|
||||||
return p.arena.Reserve(sz)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (p *Passthrough) Commit(pkt []byte) error {
|
|
||||||
p.slots = append(p.slots, pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (p *Passthrough) Flush() error {
|
|
||||||
var firstErr error
|
|
||||||
for _, s := range p.slots {
|
|
||||||
_, err := p.out.Write(s)
|
|
||||||
if err != nil && firstErr == nil {
|
|
||||||
firstErr = err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
clear(p.slots)
|
|
||||||
p.slots = p.slots[:0]
|
|
||||||
p.arena.Reset()
|
|
||||||
return firstErr
|
|
||||||
}
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
type RxBatcher interface {
|
|
||||||
// Reserve creates a pkt to borrow
|
|
||||||
Reserve(sz int) []byte
|
|
||||||
// Commit borrows pkt. The caller must keep pkt valid until the next Flush
|
|
||||||
Commit(pkt []byte) error
|
|
||||||
// Flush emits every queued packet in arrival order. Returns the
|
|
||||||
// first error observed; keeps draining so one bad packet doesn't hold up
|
|
||||||
// the rest. After Flush returns, borrowed payload slices may be recycled.
|
|
||||||
Flush() error
|
|
||||||
}
|
|
||||||
@@ -1,743 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"context"
|
|
||||||
"encoding/binary"
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
|
||||||
"net/netip"
|
|
||||||
"slices"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
|
||||||
|
|
||||||
// ipProtoTCP is the IANA protocol number for TCP. Hardcoded instead of
|
|
||||||
// reaching for golang.org/x/sys/unix — that package doesn't define the
|
|
||||||
// constant on Windows, which would break cross-compiles even though this
|
|
||||||
// file runs unchanged on every platform.
|
|
||||||
const ipProtoTCP = 6
|
|
||||||
|
|
||||||
// tcpCoalesceBufSize caps total bytes per superpacket. Mirrors the kernel's
|
|
||||||
// sk_gso_max_size of ~64KiB; anything beyond this would be rejected anyway.
|
|
||||||
const tcpCoalesceBufSize = 65535
|
|
||||||
|
|
||||||
// tcpCoalesceMaxSegs caps how many segments we'll coalesce into a single
|
|
||||||
// superpacket. Keeping this well below the kernel's TSO ceiling bounds
|
|
||||||
// latency.
|
|
||||||
const tcpCoalesceMaxSegs = 64
|
|
||||||
|
|
||||||
// tcpCoalesceHdrCap is the scratch space we copy a seed's IP+TCP header
|
|
||||||
// into. IPv6 (40) + TCP with full options (60) = 100 bytes.
|
|
||||||
const tcpCoalesceHdrCap = 100
|
|
||||||
|
|
||||||
// coalesceSlot is one entry in the coalescer's ordered event queue. When
|
|
||||||
// passthrough is true the slot holds a single borrowed packet that must be
|
|
||||||
// emitted verbatim (non-TCP, non-admissible TCP, or oversize seed). When
|
|
||||||
// passthrough is false the slot is an in-progress coalesced superpacket:
|
|
||||||
// hdrBuf is a mutable copy of the seed's IP+TCP header (we patch total
|
|
||||||
// length and pseudo-header partial at flush), and payIovs are *borrowed*
|
|
||||||
// slices from the caller's plaintext buffers — no payload is ever copied.
|
|
||||||
// The caller (listenOut) must keep those buffers alive until Flush.
|
|
||||||
type coalesceSlot struct {
|
|
||||||
passthrough bool
|
|
||||||
rawPkt []byte // borrowed when passthrough
|
|
||||||
|
|
||||||
fk flowKey
|
|
||||||
hdrBuf [tcpCoalesceHdrCap]byte
|
|
||||||
hdrLen int
|
|
||||||
ipHdrLen int
|
|
||||||
isV6 bool
|
|
||||||
gsoSize int
|
|
||||||
numSeg int
|
|
||||||
totalPay int
|
|
||||||
nextSeq uint32
|
|
||||||
// psh closes the chain: set when the last-accepted segment had PSH or
|
|
||||||
// was sub-gsoSize. No further appends after that.
|
|
||||||
psh bool
|
|
||||||
payIovs [][]byte
|
|
||||||
}
|
|
||||||
|
|
||||||
// TCPCoalescer accumulates adjacent in-flow TCP data segments across
|
|
||||||
// multiple concurrent flows and emits each flow's run as a single TSO
|
|
||||||
// superpacket via tio.GSOWriter. All output — coalesced or not — is
|
|
||||||
// deferred until Flush so arrival order is preserved on the wire. Owns
|
|
||||||
// no locks; one coalescer per TUN write queue.
|
|
||||||
type TCPCoalescer struct {
|
|
||||||
plainW io.Writer
|
|
||||||
gsoW tio.GSOWriter // nil when the queue doesn't support TSO
|
|
||||||
|
|
||||||
// slots is the ordered event queue. Flush walks it once and emits each
|
|
||||||
// entry as either a WriteGSO (coalesced) or a plainW.Write (passthrough).
|
|
||||||
slots []*coalesceSlot
|
|
||||||
// openSlots maps a flow key to its most recent non-sealed slot, so new
|
|
||||||
// segments can extend an in-progress superpacket in O(1). Slots are
|
|
||||||
// removed from this map when they close (PSH or short-last-segment),
|
|
||||||
// when a non-admissible packet for that flow arrives, or in Flush.
|
|
||||||
openSlots map[flowKey]*coalesceSlot
|
|
||||||
// lastSlot caches the most recently touched open slot. Steady-state
|
|
||||||
// bulk traffic is dominated by a single flow, so comparing the
|
|
||||||
// incoming key against the cached slot's own fk lets the hot path
|
|
||||||
// skip the map lookup (and the aeshash of a 38-byte key) entirely.
|
|
||||||
// Kept in lockstep with openSlots: nil whenever the slot it pointed
|
|
||||||
// at is removed/sealed.
|
|
||||||
lastSlot *coalesceSlot
|
|
||||||
pool []*coalesceSlot // free list for reuse
|
|
||||||
|
|
||||||
// arena is injected; the coalescer borrows slices from it via Reserve
|
|
||||||
// and tells it to release them via Reset on Flush. When wrapped in
|
|
||||||
// MultiCoalescer the same *Arena is shared with the other lanes so
|
|
||||||
// there's exactly one backing slab per Multi instance.
|
|
||||||
arena *util.Arena
|
|
||||||
l *slog.Logger
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewTCPCoalescer(w tio.Queue, l *slog.Logger, arena *util.Arena) *TCPCoalescer {
|
|
||||||
c := &TCPCoalescer{
|
|
||||||
plainW: w,
|
|
||||||
slots: make([]*coalesceSlot, 0, initialSlots),
|
|
||||||
openSlots: make(map[flowKey]*coalesceSlot, initialSlots),
|
|
||||||
pool: make([]*coalesceSlot, 0, initialSlots),
|
|
||||||
arena: arena,
|
|
||||||
l: l,
|
|
||||||
}
|
|
||||||
if gw, ok := tio.SupportsGSO(w, wire.GSOProtoTCP); ok {
|
|
||||||
c.gsoW = gw
|
|
||||||
}
|
|
||||||
return c
|
|
||||||
}
|
|
||||||
|
|
||||||
// parsedTCP holds the fields extracted from a single parse so later steps
|
|
||||||
// (admission, slot lookup, canAppend) don't re-walk the header.
|
|
||||||
type parsedTCP struct {
|
|
||||||
fk flowKey
|
|
||||||
ipHdrLen int
|
|
||||||
tcpHdrLen int
|
|
||||||
hdrLen int
|
|
||||||
payLen int
|
|
||||||
seq uint32
|
|
||||||
flags byte
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseTCPBase extracts the flow key and IP/TCP offsets for any TCP packet,
|
|
||||||
// regardless of whether it's admissible for coalescing. Returns ok=false
|
|
||||||
// for non-TCP or malformed input. Accepts IPv4 (no options, no fragmentation)
|
|
||||||
// and IPv6 (no extension headers).
|
|
||||||
func parseTCPBase(pkt []byte) (parsedTCP, bool) {
|
|
||||||
var p parsedTCP
|
|
||||||
ip, ok := parseIPPrologue(pkt, ipProtoTCP)
|
|
||||||
if !ok {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
pkt = ip.pkt
|
|
||||||
p.fk = ip.fk
|
|
||||||
p.ipHdrLen = ip.ipHdrLen
|
|
||||||
|
|
||||||
if len(pkt) < p.ipHdrLen+20 {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
tcpOff := int(pkt[p.ipHdrLen+12]>>4) * 4
|
|
||||||
if tcpOff < 20 || tcpOff > 60 {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
if len(pkt) < p.ipHdrLen+tcpOff {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
p.tcpHdrLen = tcpOff
|
|
||||||
p.hdrLen = p.ipHdrLen + tcpOff
|
|
||||||
p.payLen = len(pkt) - p.hdrLen
|
|
||||||
p.seq = binary.BigEndian.Uint32(pkt[p.ipHdrLen+4 : p.ipHdrLen+8])
|
|
||||||
p.flags = pkt[p.ipHdrLen+13]
|
|
||||||
p.fk.sport = binary.BigEndian.Uint16(pkt[p.ipHdrLen : p.ipHdrLen+2])
|
|
||||||
p.fk.dport = binary.BigEndian.Uint16(pkt[p.ipHdrLen+2 : p.ipHdrLen+4])
|
|
||||||
return p, true
|
|
||||||
}
|
|
||||||
|
|
||||||
// TCP flag bits (byte 13 of the TCP header). Only the bits actually consulted
|
|
||||||
// by the coalescer are named; FIN/SYN/RST/URG/CWR are rejected via the
|
|
||||||
// negative mask in coalesceable, not by name.
|
|
||||||
const (
|
|
||||||
tcpFlagPsh = 0x08
|
|
||||||
tcpFlagAck = 0x10
|
|
||||||
tcpFlagEce = 0x40
|
|
||||||
)
|
|
||||||
|
|
||||||
// coalesceable reports whether a parsed TCP segment is eligible for
|
|
||||||
// coalescing. Accepts ACK, ACK|PSH, ACK|ECE, ACK|PSH|ECE with a
|
|
||||||
// non-empty payload. CWR is excluded because it marks a one-shot
|
|
||||||
// congestion-window-reduced transition the receiver must observe at a
|
|
||||||
// segment boundary.
|
|
||||||
func (p parsedTCP) coalesceable() bool {
|
|
||||||
if p.flags&tcpFlagAck == 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if p.flags&^(tcpFlagAck|tcpFlagPsh|tcpFlagEce) != 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return p.payLen > 0
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *TCPCoalescer) Reserve(sz int) []byte {
|
|
||||||
return c.arena.Reserve(sz)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Commit borrows pkt. The caller must keep pkt valid until the next Flush,
|
|
||||||
// whether or not the packet was coalesced — passthrough (non-admissible)
|
|
||||||
// packets are queued and written at Flush time, not synchronously.
|
|
||||||
func (c *TCPCoalescer) Commit(pkt []byte) error {
|
|
||||||
if c.gsoW == nil {
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
info, ok := parseTCPBase(pkt)
|
|
||||||
if !ok {
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
return c.commitParsed(pkt, info)
|
|
||||||
}
|
|
||||||
|
|
||||||
// commitParsed is the post-parse half of Commit. The caller must have
|
|
||||||
// already verified parseTCPBase succeeded (info is a valid TCP parse).
|
|
||||||
// Used by MultiCoalescer.Commit to avoid re-walking the IP/TCP header
|
|
||||||
// after the dispatcher has already done so.
|
|
||||||
func (c *TCPCoalescer) commitParsed(pkt []byte, info parsedTCP) error {
|
|
||||||
if c.gsoW == nil {
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if !info.coalesceable() {
|
|
||||||
// TCP but not admissible (SYN/FIN/RST/URG/CWR or zero-payload).
|
|
||||||
// Seal this flow's open slot so later in-flow packets don't extend
|
|
||||||
// it and accidentally reorder past this passthrough.
|
|
||||||
if last := c.lastSlot; last != nil && last.fk == info.fk {
|
|
||||||
c.lastSlot = nil
|
|
||||||
}
|
|
||||||
delete(c.openSlots, info.fk)
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// Single-flow fast path: with only one open flow the cache hits every
|
|
||||||
// packet, and len(openSlots)==1 lets us skip the 38-byte fk compare
|
|
||||||
// when there are multiple flows in flight (where the hit rate would
|
|
||||||
// be ~0 and the compare is pure overhead).
|
|
||||||
var open *coalesceSlot
|
|
||||||
if last := c.lastSlot; last != nil && len(c.openSlots) == 1 && last.fk == info.fk {
|
|
||||||
open = last
|
|
||||||
} else {
|
|
||||||
open = c.openSlots[info.fk]
|
|
||||||
}
|
|
||||||
if open != nil {
|
|
||||||
if c.canAppend(open, pkt, info) {
|
|
||||||
c.appendPayload(open, pkt, info)
|
|
||||||
if open.psh {
|
|
||||||
delete(c.openSlots, info.fk)
|
|
||||||
c.lastSlot = nil
|
|
||||||
} else {
|
|
||||||
c.lastSlot = open
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
// Can't extend — seal it and fall through to seed a fresh slot.
|
|
||||||
delete(c.openSlots, info.fk)
|
|
||||||
if c.lastSlot == open {
|
|
||||||
c.lastSlot = nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
c.seed(pkt, info)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// Flush emits every queued event in (per-flow) seq order. Coalesced slots
|
|
||||||
// go out via WriteGSO; passthrough slots go out via plainW.Write.
|
|
||||||
// reorderForFlush first sorts each flow's slots into TCP-seq order within
|
|
||||||
// passthrough-bounded segments and merges contiguous adjacent slots, so
|
|
||||||
// any wire-side reorder that crossed an rxOrder batch boundary doesn't
|
|
||||||
// get amplified into kernel-visible reorder by the slot machinery.
|
|
||||||
// Returns the first error observed; keeps draining so one bad packet
|
|
||||||
// doesn't hold up the rest. After Flush returns, borrowed payload slices
|
|
||||||
// may be recycled.
|
|
||||||
func (c *TCPCoalescer) Flush() error {
|
|
||||||
c.reorderForFlush()
|
|
||||||
var first error
|
|
||||||
for _, s := range c.slots {
|
|
||||||
var err error
|
|
||||||
if s.passthrough {
|
|
||||||
_, err = c.plainW.Write(s.rawPkt)
|
|
||||||
} else {
|
|
||||||
err = c.flushSlot(s)
|
|
||||||
}
|
|
||||||
if err != nil && first == nil {
|
|
||||||
first = err
|
|
||||||
}
|
|
||||||
c.release(s)
|
|
||||||
}
|
|
||||||
clear(c.slots)
|
|
||||||
c.slots = c.slots[:0]
|
|
||||||
clear(c.openSlots)
|
|
||||||
c.lastSlot = nil
|
|
||||||
|
|
||||||
c.arena.Reset()
|
|
||||||
return first
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *TCPCoalescer) addPassthrough(pkt []byte) {
|
|
||||||
s := c.take()
|
|
||||||
s.passthrough = true
|
|
||||||
s.rawPkt = pkt
|
|
||||||
c.slots = append(c.slots, s)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *TCPCoalescer) seed(pkt []byte, info parsedTCP) {
|
|
||||||
if info.hdrLen > tcpCoalesceHdrCap || info.hdrLen+info.payLen > tcpCoalesceBufSize {
|
|
||||||
// Pathological shape — can't fit our scratch, emit as-is.
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
s := c.take()
|
|
||||||
s.passthrough = false
|
|
||||||
s.rawPkt = nil
|
|
||||||
copy(s.hdrBuf[:], pkt[:info.hdrLen])
|
|
||||||
s.hdrLen = info.hdrLen
|
|
||||||
s.ipHdrLen = info.ipHdrLen
|
|
||||||
s.isV6 = info.fk.isV6
|
|
||||||
s.fk = info.fk
|
|
||||||
s.gsoSize = info.payLen
|
|
||||||
s.numSeg = 1
|
|
||||||
s.totalPay = info.payLen
|
|
||||||
s.nextSeq = info.seq + uint32(info.payLen)
|
|
||||||
s.psh = info.flags&tcpFlagPsh != 0
|
|
||||||
s.payIovs = append(s.payIovs[:0], pkt[info.hdrLen:info.hdrLen+info.payLen])
|
|
||||||
c.slots = append(c.slots, s)
|
|
||||||
if !s.psh {
|
|
||||||
c.openSlots[info.fk] = s
|
|
||||||
c.lastSlot = s
|
|
||||||
} else if last := c.lastSlot; last != nil && last.fk == info.fk {
|
|
||||||
// PSH-on-seed seals the slot immediately. Any prior cached open
|
|
||||||
// slot for this flow has just been sealed-and-replaced by this
|
|
||||||
// passthrough-shaped seed, so drop the cache too.
|
|
||||||
c.lastSlot = nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// canAppend reports whether info's packet extends the slot's seed: same
|
|
||||||
// header shape and stable contents, adjacent seq, not oversized, chain not
|
|
||||||
// closed.
|
|
||||||
func (c *TCPCoalescer) canAppend(s *coalesceSlot, pkt []byte, info parsedTCP) bool {
|
|
||||||
if s.psh {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if info.hdrLen != s.hdrLen {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if info.seq != s.nextSeq {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if s.numSeg >= tcpCoalesceMaxSegs {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if info.payLen > s.gsoSize {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if s.hdrLen+s.totalPay+info.payLen > tcpCoalesceBufSize {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
// ECE state must be stable across a burst — receivers expect the
|
|
||||||
// flag set on every segment of a CE-echoing window or none.
|
|
||||||
seedFlags := s.hdrBuf[s.ipHdrLen+13]
|
|
||||||
if (seedFlags^info.flags)&tcpFlagEce != 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !headersMatch(s.hdrBuf[:s.hdrLen], pkt[:info.hdrLen], s.isV6, s.ipHdrLen) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *TCPCoalescer) appendPayload(s *coalesceSlot, pkt []byte, info parsedTCP) {
|
|
||||||
s.payIovs = append(s.payIovs, pkt[info.hdrLen:info.hdrLen+info.payLen])
|
|
||||||
s.numSeg++
|
|
||||||
s.totalPay += info.payLen
|
|
||||||
s.nextSeq = info.seq + uint32(info.payLen)
|
|
||||||
if info.flags&tcpFlagPsh != 0 {
|
|
||||||
// Propagate PSH into the seed header so kernel TSO sets it on the
|
|
||||||
// last segment. Without this the sender's push signal is dropped.
|
|
||||||
s.hdrBuf[s.ipHdrLen+13] |= tcpFlagPsh
|
|
||||||
}
|
|
||||||
// Merge IP-level CE marks into the seed: headersMatch ignores ECN, so
|
|
||||||
// this is the one place the signal is preserved.
|
|
||||||
mergeECNIntoSeed(s.hdrBuf[:s.ipHdrLen], pkt[:s.ipHdrLen], s.isV6)
|
|
||||||
if info.payLen < s.gsoSize || info.flags&tcpFlagPsh != 0 {
|
|
||||||
s.psh = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *TCPCoalescer) take() *coalesceSlot {
|
|
||||||
if n := len(c.pool); n > 0 {
|
|
||||||
s := c.pool[n-1]
|
|
||||||
c.pool[n-1] = nil
|
|
||||||
c.pool = c.pool[:n-1]
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
return &coalesceSlot{}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *TCPCoalescer) release(s *coalesceSlot) {
|
|
||||||
s.passthrough = false
|
|
||||||
s.rawPkt = nil
|
|
||||||
clear(s.payIovs)
|
|
||||||
s.payIovs = s.payIovs[:0]
|
|
||||||
s.numSeg = 0
|
|
||||||
s.totalPay = 0
|
|
||||||
s.psh = false
|
|
||||||
c.pool = append(c.pool, s)
|
|
||||||
}
|
|
||||||
|
|
||||||
// flushSlot patches the header and calls WriteGSO. Does not remove the
|
|
||||||
// slot from c.slots.
|
|
||||||
func (c *TCPCoalescer) flushSlot(s *coalesceSlot) error {
|
|
||||||
total := s.hdrLen + s.totalPay
|
|
||||||
l4Len := total - s.ipHdrLen
|
|
||||||
hdr := s.hdrBuf[:s.hdrLen]
|
|
||||||
|
|
||||||
if s.isV6 {
|
|
||||||
binary.BigEndian.PutUint16(hdr[4:6], uint16(l4Len))
|
|
||||||
} else {
|
|
||||||
binary.BigEndian.PutUint16(hdr[2:4], uint16(total))
|
|
||||||
hdr[10] = 0
|
|
||||||
hdr[11] = 0
|
|
||||||
binary.BigEndian.PutUint16(hdr[10:12], ipv4HdrChecksum(hdr[:s.ipHdrLen]))
|
|
||||||
}
|
|
||||||
|
|
||||||
var psum uint32
|
|
||||||
if s.isV6 {
|
|
||||||
psum = pseudoSumIPv6(hdr[8:24], hdr[24:40], ipProtoTCP, l4Len)
|
|
||||||
} else {
|
|
||||||
psum = pseudoSumIPv4(hdr[12:16], hdr[16:20], ipProtoTCP, l4Len)
|
|
||||||
}
|
|
||||||
tcsum := s.ipHdrLen + 16
|
|
||||||
binary.BigEndian.PutUint16(hdr[tcsum:tcsum+2], foldOnceNoInvert(psum))
|
|
||||||
|
|
||||||
return c.gsoW.WriteGSO(hdr[:s.ipHdrLen], hdr[s.ipHdrLen:], s.payIovs, wire.GSOProtoTCP)
|
|
||||||
}
|
|
||||||
|
|
||||||
// headersMatch compares two IP+TCP header prefixes for byte-for-byte
|
|
||||||
// equality on every field that must be identical across coalesced
|
|
||||||
// segments. Size/IPID/IPCsum/seq/flags/tcpCsum are masked out, as is the
|
|
||||||
// 2-bit IP-level ECN field — appendPayload merges CE into the seed.
|
|
||||||
func headersMatch(a, b []byte, isV6 bool, ipHdrLen int) bool {
|
|
||||||
if len(a) != len(b) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !ipHeadersMatch(a, b, isV6) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
// TCP: compare [0:4] ports, [8:13] ack+dataoff, [14:16] window,
|
|
||||||
// [18:tcpHdrLen] options (incl. urgent).
|
|
||||||
tcp := ipHdrLen
|
|
||||||
if !bytes.Equal(a[tcp:tcp+4], b[tcp:tcp+4]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !bytes.Equal(a[tcp+8:tcp+13], b[tcp+8:tcp+13]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !bytes.Equal(a[tcp+14:tcp+16], b[tcp+14:tcp+16]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !bytes.Equal(a[tcp+18:], b[tcp+18:]) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
// reorderForFlush neutralizes wire-side reorder that the rxOrder buffer
|
|
||||||
// couldn't catch (anything crossing a recvmmsg batch boundary). Without
|
|
||||||
// this pass a small wire reorder — counter 250 arriving in batch K when
|
|
||||||
// 200..249 are coming in batch K+1 — would seed an out-of-seq slot first
|
|
||||||
// and emit it ahead of the lower-seq slot, manifesting at the inner TCP
|
|
||||||
// receiver as a much larger reorder than the wire actually had.
|
|
||||||
//
|
|
||||||
// Two phases:
|
|
||||||
// 1. Sort each passthrough-bounded segment of c.slots by (flow, seq).
|
|
||||||
// Cross-flow ordering inside a segment isn't preserved (it never was
|
|
||||||
// and doesn't matter for any single flow's TCP correctness).
|
|
||||||
// 2. Sweep once and merge adjacent same-flow slots whose ranges are now
|
|
||||||
// contiguous AND whose tail is gsoSize-aligned. The tail constraint
|
|
||||||
// matters because the kernel TSO splitter chops at gsoSize from the
|
|
||||||
// start of the merged payload — a short segment in the middle would
|
|
||||||
// desynchronize every later segment.
|
|
||||||
//
|
|
||||||
// Passthrough slots act as barriers: the merge check skips them on either
|
|
||||||
// side, so a SYN/FIN/RST/CWR is never reordered relative to its flow's
|
|
||||||
// data.
|
|
||||||
func (c *TCPCoalescer) reorderForFlush() {
|
|
||||||
if len(c.slots) <= 1 {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
runStart := 0
|
|
||||||
for i := 0; i <= len(c.slots); i++ {
|
|
||||||
if i < len(c.slots) && !c.slots[i].passthrough {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
c.sortRun(c.slots[runStart:i])
|
|
||||||
runStart = i + 1
|
|
||||||
}
|
|
||||||
out := c.slots[:0]
|
|
||||||
logged := false
|
|
||||||
for _, s := range c.slots {
|
|
||||||
if n := len(out); n > 0 {
|
|
||||||
prev := out[n-1]
|
|
||||||
if !prev.passthrough && !s.passthrough && prev.fk == s.fk {
|
|
||||||
// Same-flow neighbors after sort. If they aren't seq-
|
|
||||||
// contiguous it's a real gap — packets the wire reordered
|
|
||||||
// across batches, or actual loss before nebula. Log it so
|
|
||||||
// the operator can quantify how often it happens; the data
|
|
||||||
// itself still emits in seq order, kernel TCP handles the
|
|
||||||
// gap via its OOO queue.
|
|
||||||
if c.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
if prev.nextSeq != slotSeedSeq(s) {
|
|
||||||
logged = true
|
|
||||||
gap := int64(slotSeedSeq(s)) - int64(prev.nextSeq)
|
|
||||||
c.l.Debug("tcp coalesce: cross-slot seq gap",
|
|
||||||
"src", flowKeyAddr(s.fk, false),
|
|
||||||
"dst", flowKeyAddr(s.fk, true),
|
|
||||||
"sport", s.fk.sport,
|
|
||||||
"dport", s.fk.dport,
|
|
||||||
"prev_seed_seq", slotSeedSeq(prev),
|
|
||||||
"prev_next_seq", prev.nextSeq,
|
|
||||||
"this_seed_seq", slotSeedSeq(s),
|
|
||||||
"gap_bytes", gap,
|
|
||||||
"prev_seg_count", prev.numSeg,
|
|
||||||
"prev_total_pay", prev.totalPay,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if canMergeSlots(prev, s) {
|
|
||||||
mergeSlots(prev, s)
|
|
||||||
c.release(s)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
out = append(out, s)
|
|
||||||
}
|
|
||||||
if logged {
|
|
||||||
c.l.Warn("==== end of batch ====")
|
|
||||||
}
|
|
||||||
c.slots = out
|
|
||||||
}
|
|
||||||
|
|
||||||
// flowKeyAddr returns the src or dst address from fk as a netip.Addr for
|
|
||||||
// logging. Only used on the cold gap-log path so the netip allocation
|
|
||||||
// doesn't matter.
|
|
||||||
func flowKeyAddr(fk flowKey, dst bool) netip.Addr {
|
|
||||||
src := fk.src
|
|
||||||
if dst {
|
|
||||||
src = fk.dst
|
|
||||||
}
|
|
||||||
if fk.isV6 {
|
|
||||||
return netip.AddrFrom16(src)
|
|
||||||
}
|
|
||||||
var v4 [4]byte
|
|
||||||
copy(v4[:], src[:4])
|
|
||||||
return netip.AddrFrom4(v4)
|
|
||||||
}
|
|
||||||
|
|
||||||
// sortRun stable-sorts run by (flowKey, seedSeq) so each flow's slots
|
|
||||||
// cluster together in seq order, ready for the merge sweep. Stable so
|
|
||||||
// equal-key slots keep their original relative position (defensive — a
|
|
||||||
// duplicate seedSeq would already mean something's wrong upstream).
|
|
||||||
func (c *TCPCoalescer) sortRun(run []*coalesceSlot) {
|
|
||||||
if len(run) <= 1 {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
// slices.SortStableFunc with a free, non-capturing comparator avoids the
|
|
||||||
// reflection + closure-escape allocations that sort.SliceStable forces.
|
|
||||||
slices.SortStableFunc(run, compareCoalesceSlots)
|
|
||||||
}
|
|
||||||
|
|
||||||
func compareCoalesceSlots(a, b *coalesceSlot) int {
|
|
||||||
if cmp := flowKeyCompare(a.fk, b.fk); cmp != 0 {
|
|
||||||
return cmp
|
|
||||||
}
|
|
||||||
aSeq, bSeq := slotSeedSeq(a), slotSeedSeq(b)
|
|
||||||
if aSeq == bSeq {
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
if tcpSeqLess(aSeq, bSeq) {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
// slotSeedSeq returns the TCP seq of the slot's seed (first segment).
|
|
||||||
// nextSeq tracks the seq just past the last appended byte; subtracting
|
|
||||||
// totalPay walks back to the seed. uint32 wraparound is the right TCP
|
|
||||||
// arithmetic so no special-casing is needed.
|
|
||||||
func slotSeedSeq(s *coalesceSlot) uint32 {
|
|
||||||
return s.nextSeq - uint32(s.totalPay)
|
|
||||||
}
|
|
||||||
|
|
||||||
// tcpSeqLess reports whether a precedes b in TCP serial-number arithmetic
|
|
||||||
// (RFC 1323 §2.3). The signed int32 cast turns the modular subtraction
|
|
||||||
// into the right comparison even across the 2^32 wrap.
|
|
||||||
func tcpSeqLess(a, b uint32) bool {
|
|
||||||
return int32(a-b) < 0
|
|
||||||
}
|
|
||||||
|
|
||||||
// flowKeyCompare orders flowKeys deterministically. The exact ordering
|
|
||||||
// is irrelevant — only that same-flow slots cluster together so the
|
|
||||||
// post-sort sweep can merge contiguous pairs.
|
|
||||||
func flowKeyCompare(a, b flowKey) int {
|
|
||||||
// Cheap scalar fields first so most non-matching keys short-circuit
|
|
||||||
// without ever calling bytes.Compare. sport is the ephemeral port on
|
|
||||||
// egress flows and discriminates fastest. For matching keys (same
|
|
||||||
// flow), array equality on src/dst inlines to word-sized compares,
|
|
||||||
// so we only pay bytes.Compare when the arrays actually differ.
|
|
||||||
if a.sport != b.sport {
|
|
||||||
if a.sport < b.sport {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
if a.dport != b.dport {
|
|
||||||
if a.dport < b.dport {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
if a.dst != b.dst {
|
|
||||||
return bytes.Compare(a.dst[:], b.dst[:])
|
|
||||||
}
|
|
||||||
if a.src != b.src {
|
|
||||||
return bytes.Compare(a.src[:], b.src[:])
|
|
||||||
}
|
|
||||||
if a.isV6 != b.isV6 {
|
|
||||||
if !a.isV6 {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
// canMergeSlots reports whether s can fold into prev as one merged TSO
|
|
||||||
// superpacket. Same flow, contiguous TCP byte range, equal gsoSize, and
|
|
||||||
// fits within the kernel TSO limits. The tail-of-prev check rejects any
|
|
||||||
// merge whose first slot ended on a sub-gsoSize segment — kernel TSO
|
|
||||||
// would split the merged skb at gsoSize boundaries from the start, so a
|
|
||||||
// short segment in the middle would corrupt every later segment. PSH and
|
|
||||||
// ECE state must agree across both slots: PSH is a semantic delimiter
|
|
||||||
// (preserving the sender's push boundary) and ECE state must be uniform
|
|
||||||
// across a window (the same rule canAppend enforces for in-flow appends).
|
|
||||||
//
|
|
||||||
// Note: a slot sealed by reorder (canAppend returned false on seq
|
|
||||||
// mismatch) keeps psh=false, so this restriction does not block the
|
|
||||||
// reorder-fix merge — only legitimate PSH-set seals.
|
|
||||||
func canMergeSlots(prev, s *coalesceSlot) bool {
|
|
||||||
if prev.psh {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if prev.fk != s.fk {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if prev.gsoSize != s.gsoSize {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if prev.nextSeq != slotSeedSeq(s) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if prev.numSeg+s.numSeg > tcpCoalesceMaxSegs {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if prev.hdrLen+prev.totalPay+s.totalPay > tcpCoalesceBufSize {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if len(prev.payIovs[len(prev.payIovs)-1]) != prev.gsoSize {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
prevFlags := prev.hdrBuf[prev.ipHdrLen+13]
|
|
||||||
sFlags := s.hdrBuf[s.ipHdrLen+13]
|
|
||||||
if (prevFlags^sFlags)&tcpFlagEce != 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !headersMatch(prev.hdrBuf[:prev.hdrLen], s.hdrBuf[:s.hdrLen], prev.isV6, prev.ipHdrLen) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
// mergeSlots folds src into dst in place: payIovs concatenated, counters
|
|
||||||
// and totals updated, PSH and IP-level CE bits OR'd into the seed header
|
|
||||||
// so neither the push signal nor a CE mark is lost. The seed header's
|
|
||||||
// seq, gsoSize, and fk are unchanged. Caller is responsible for releasing
|
|
||||||
// src (it's no longer in c.slots after this call).
|
|
||||||
func mergeSlots(dst, src *coalesceSlot) {
|
|
||||||
dst.payIovs = append(dst.payIovs, src.payIovs...)
|
|
||||||
dst.numSeg += src.numSeg
|
|
||||||
dst.totalPay += src.totalPay
|
|
||||||
dst.nextSeq = src.nextSeq
|
|
||||||
if src.psh {
|
|
||||||
dst.psh = true
|
|
||||||
dst.hdrBuf[dst.ipHdrLen+13] |= tcpFlagPsh
|
|
||||||
}
|
|
||||||
mergeECNIntoSeed(dst.hdrBuf[:dst.ipHdrLen], src.hdrBuf[:src.ipHdrLen], dst.isV6)
|
|
||||||
}
|
|
||||||
|
|
||||||
// ipv4HdrChecksum computes the IPv4 header checksum over hdr (which must
|
|
||||||
// already have its checksum field zeroed) and returns the folded/inverted
|
|
||||||
// 16-bit value to store.
|
|
||||||
func ipv4HdrChecksum(hdr []byte) uint16 {
|
|
||||||
var sum uint32
|
|
||||||
for i := 0; i+1 < len(hdr); i += 2 {
|
|
||||||
sum += uint32(binary.BigEndian.Uint16(hdr[i : i+2]))
|
|
||||||
}
|
|
||||||
if len(hdr)%2 == 1 {
|
|
||||||
sum += uint32(hdr[len(hdr)-1]) << 8
|
|
||||||
}
|
|
||||||
for sum>>16 != 0 {
|
|
||||||
sum = (sum & 0xffff) + (sum >> 16)
|
|
||||||
}
|
|
||||||
return ^uint16(sum)
|
|
||||||
}
|
|
||||||
|
|
||||||
// pseudoSumIPv4 / pseudoSumIPv6 build the L4 pseudo-header partial sum
|
|
||||||
// expected by the virtio NEEDS_CSUM kernel path: the 32-bit accumulator
|
|
||||||
// before folding. proto selects the L4 (TCP or UDP); the UDP coalescer
|
|
||||||
// reuses these helpers.
|
|
||||||
func pseudoSumIPv4(src, dst []byte, proto byte, l4Len int) uint32 {
|
|
||||||
var sum uint32
|
|
||||||
sum += uint32(binary.BigEndian.Uint16(src[0:2]))
|
|
||||||
sum += uint32(binary.BigEndian.Uint16(src[2:4]))
|
|
||||||
sum += uint32(binary.BigEndian.Uint16(dst[0:2]))
|
|
||||||
sum += uint32(binary.BigEndian.Uint16(dst[2:4]))
|
|
||||||
sum += uint32(proto)
|
|
||||||
sum += uint32(l4Len)
|
|
||||||
return sum
|
|
||||||
}
|
|
||||||
|
|
||||||
func pseudoSumIPv6(src, dst []byte, proto byte, l4Len int) uint32 {
|
|
||||||
var sum uint32
|
|
||||||
for i := 0; i < 16; i += 2 {
|
|
||||||
sum += uint32(binary.BigEndian.Uint16(src[i : i+2]))
|
|
||||||
sum += uint32(binary.BigEndian.Uint16(dst[i : i+2]))
|
|
||||||
}
|
|
||||||
sum += uint32(l4Len >> 16)
|
|
||||||
sum += uint32(l4Len & 0xffff)
|
|
||||||
sum += uint32(proto)
|
|
||||||
return sum
|
|
||||||
}
|
|
||||||
|
|
||||||
// foldOnceNoInvert folds the 32-bit accumulator to 16 bits and returns it
|
|
||||||
// unchanged (no one's complement). This is what virtio NEEDS_CSUM wants in
|
|
||||||
// the L4 checksum field — the kernel will add the payload sum and invert.
|
|
||||||
func foldOnceNoInvert(sum uint32) uint16 {
|
|
||||||
for sum>>16 != 0 {
|
|
||||||
sum = (sum & 0xffff) + (sum >> 16)
|
|
||||||
}
|
|
||||||
return uint16(sum)
|
|
||||||
}
|
|
||||||
@@ -1,244 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"runtime"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/test"
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
|
||||||
|
|
||||||
// nopTunWriter is a zero-alloc tio.GSOWriter for benchmarks. Discards
|
|
||||||
// everything but satisfies the interface the coalescer detects.
|
|
||||||
type nopTunWriter struct{}
|
|
||||||
|
|
||||||
func (nopTunWriter) Write(p []byte) (int, error) { return len(p), nil }
|
|
||||||
func (nopTunWriter) Read(_ []wire.TunPacket, _ []byte) (int, error) { return 0, nil }
|
|
||||||
func (nopTunWriter) Close() error { return nil }
|
|
||||||
func (nopTunWriter) WriteGSO(hdr []byte, transportHdr []byte, pays [][]byte, _ wire.GSOProto) error {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
func (nopTunWriter) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{TSO: true, USO: true}
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildTCPv4BulkFlow returns a slice of N adjacent ACK-only TCP segments
|
|
||||||
// on a single 5-tuple, each carrying payloadLen bytes. Seq numbers are
|
|
||||||
// contiguous so every packet is coalesceable onto the previous one.
|
|
||||||
func buildTCPv4BulkFlow(n, payloadLen int) [][]byte {
|
|
||||||
pkts := make([][]byte, n)
|
|
||||||
pay := make([]byte, payloadLen)
|
|
||||||
seq := uint32(1000)
|
|
||||||
for i := range n {
|
|
||||||
pkts[i] = buildTCPv4(seq, tcpAck, pay)
|
|
||||||
seq += uint32(payloadLen)
|
|
||||||
}
|
|
||||||
return pkts
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildTCPv4Interleaved returns nFlows * perFlow packets with per-flow
|
|
||||||
// seq continuity but round-robin across flows — worst case for any
|
|
||||||
// "last-slot" cache.
|
|
||||||
func buildTCPv4Interleaved(nFlows, perFlow, payloadLen int) [][]byte {
|
|
||||||
pay := make([]byte, payloadLen)
|
|
||||||
seqs := make([]uint32, nFlows)
|
|
||||||
for i := range seqs {
|
|
||||||
seqs[i] = uint32(1000 + i*1000000)
|
|
||||||
}
|
|
||||||
pkts := make([][]byte, 0, nFlows*perFlow)
|
|
||||||
for range perFlow {
|
|
||||||
for f := range nFlows {
|
|
||||||
sport := uint16(10000 + f)
|
|
||||||
pkts = append(pkts, buildTCPv4Ports(sport, 2000, seqs[f], tcpAck, pay))
|
|
||||||
seqs[f] += uint32(payloadLen)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return pkts
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildICMPv4 returns a minimal non-TCP packet that takes the passthrough
|
|
||||||
// branch in Commit.
|
|
||||||
func buildICMPv4() []byte {
|
|
||||||
pkt := make([]byte, 28)
|
|
||||||
pkt[0] = 0x45
|
|
||||||
binary.BigEndian.PutUint16(pkt[2:4], 28)
|
|
||||||
pkt[9] = 1 // ICMP
|
|
||||||
copy(pkt[12:16], []byte{10, 0, 0, 1})
|
|
||||||
copy(pkt[16:20], []byte{10, 0, 0, 2})
|
|
||||||
return pkt
|
|
||||||
}
|
|
||||||
|
|
||||||
// runCommitBench drives Commit over pkts batchSize at a time, flushing
|
|
||||||
// between batches, and reports per-packet cost.
|
|
||||||
func runCommitBench(b *testing.B, pkts [][]byte, batchSize int) {
|
|
||||||
b.Helper()
|
|
||||||
c := NewTCPCoalescer(nopTunWriter{}, test.NewLogger(), util.NewArena(0))
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.SetBytes(int64(len(pkts[0])))
|
|
||||||
b.ResetTimer()
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
pkt := pkts[i%len(pkts)]
|
|
||||||
if err := c.Commit(pkt); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
if (i+1)%batchSize == 0 {
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
// Drain any trailing partial batch so slot state doesn't leak across runs.
|
|
||||||
_ = c.Flush()
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkCommitSingleFlow is the bulk-TCP steady state: one flow,
|
|
||||||
// contiguous seq, 1200-byte payloads. Every packet past the seed should
|
|
||||||
// append onto the open slot. This is the case we most care about.
|
|
||||||
func BenchmarkCommitSingleFlow(b *testing.B) {
|
|
||||||
pkts := buildTCPv4BulkFlow(tcpCoalesceMaxSegs, 1200)
|
|
||||||
runCommitBench(b, pkts, tcpCoalesceMaxSegs)
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkCommitInterleaved4 has 4 concurrent bulk flows round-robined.
|
|
||||||
// A single-entry fast-path cache will miss on every packet; an N-way
|
|
||||||
// cache or map lookup carries the weight.
|
|
||||||
func BenchmarkCommitInterleaved4(b *testing.B) {
|
|
||||||
pkts := buildTCPv4Interleaved(4, tcpCoalesceMaxSegs, 1200)
|
|
||||||
runCommitBench(b, pkts, len(pkts))
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkCommitInterleaved16 stresses the map at higher flow counts.
|
|
||||||
func BenchmarkCommitInterleaved16(b *testing.B) {
|
|
||||||
pkts := buildTCPv4Interleaved(16, tcpCoalesceMaxSegs, 1200)
|
|
||||||
runCommitBench(b, pkts, len(pkts))
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkCommitPassthrough exercises the non-TCP branch: parseTCPBase
|
|
||||||
// bails early and addPassthrough is the only work.
|
|
||||||
func BenchmarkCommitPassthrough(b *testing.B) {
|
|
||||||
pkt := buildICMPv4()
|
|
||||||
pkts := make([][]byte, 64)
|
|
||||||
for i := range pkts {
|
|
||||||
pkts[i] = pkt
|
|
||||||
}
|
|
||||||
runCommitBench(b, pkts, 64)
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkCommitNonCoalesceableTCP sends SYN|ACK packets on one flow.
|
|
||||||
// Each packet takes the "TCP but not admissible" branch which does a
|
|
||||||
// map delete + passthrough. Measures the seal-without-slot cost.
|
|
||||||
func BenchmarkCommitNonCoalesceableTCP(b *testing.B) {
|
|
||||||
pay := make([]byte, 0)
|
|
||||||
pkts := make([][]byte, 64)
|
|
||||||
for i := range pkts {
|
|
||||||
pkts[i] = buildTCPv4(uint32(1000+i), tcpSyn|tcpAck, pay)
|
|
||||||
}
|
|
||||||
runCommitBench(b, pkts, 64)
|
|
||||||
}
|
|
||||||
|
|
||||||
// runMultiCommitBench drives MultiCoalescer.Commit. The dispatcher does
|
|
||||||
// the IP/L4 parse once and passes the parsed struct to the lane, so this
|
|
||||||
// is the bench that shows the savings of skipping the lane's re-parse.
|
|
||||||
func runMultiCommitBench(b *testing.B, pkts [][]byte, batchSize int) {
|
|
||||||
b.Helper()
|
|
||||||
m := NewMultiCoalescer(nopTunWriter{}, test.NewLogger(), util.NewArena(0), true, true)
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.SetBytes(int64(len(pkts[0])))
|
|
||||||
b.ResetTimer()
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
pkt := pkts[i%len(pkts)]
|
|
||||||
if err := m.Commit(pkt); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
if (i+1)%batchSize == 0 {
|
|
||||||
if err := m.Flush(); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
_ = m.Flush()
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkMultiCommitSingleFlow is the multi-lane analogue of
|
|
||||||
// BenchmarkCommitSingleFlow — same workload but routed through the
|
|
||||||
// dispatcher. The delta vs the single-lane bench measures dispatcher
|
|
||||||
// overhead.
|
|
||||||
func BenchmarkMultiCommitSingleFlow(b *testing.B) {
|
|
||||||
pkts := buildTCPv4BulkFlow(tcpCoalesceMaxSegs, 1200)
|
|
||||||
runMultiCommitBench(b, pkts, tcpCoalesceMaxSegs)
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkMultiCommitInterleaved4 mirrors BenchmarkCommitInterleaved4
|
|
||||||
// through the dispatcher.
|
|
||||||
func BenchmarkMultiCommitInterleaved4(b *testing.B) {
|
|
||||||
pkts := buildTCPv4Interleaved(4, tcpCoalesceMaxSegs, 1200)
|
|
||||||
runMultiCommitBench(b, pkts, len(pkts))
|
|
||||||
}
|
|
||||||
|
|
||||||
// flowKeyPair is one comparison input for the flowKeyCompare bench.
|
|
||||||
type flowKeyPair struct{ a, b flowKey }
|
|
||||||
|
|
||||||
// makeFlowKey builds an IPv4 flowKey from compact inputs.
|
|
||||||
func makeFlowKey(srcLow, dstLow uint32, sport, dport uint16) flowKey {
|
|
||||||
var fk flowKey
|
|
||||||
binary.BigEndian.PutUint32(fk.src[12:16], srcLow)
|
|
||||||
binary.BigEndian.PutUint32(fk.dst[12:16], dstLow)
|
|
||||||
fk.sport = sport
|
|
||||||
fk.dport = dport
|
|
||||||
return fk
|
|
||||||
}
|
|
||||||
|
|
||||||
// flowKeyCases are the workload mixes flowKeyCompare sees in practice.
|
|
||||||
// - sameFlow: equal keys; tests the equal-path cost (sort runs hit this
|
|
||||||
// repeatedly when many segments share a flow).
|
|
||||||
// - sportDiffers: same src/dst/dport, different sport — the typical
|
|
||||||
// "sibling flows from one host to one server" pattern.
|
|
||||||
// - dstDiffers: same src/sport/dport, different dst — outbound to many
|
|
||||||
// servers from a fixed local port.
|
|
||||||
// - allDiffer: every field differs; worst case for short-circuiting.
|
|
||||||
func flowKeyCases() map[string][]flowKeyPair {
|
|
||||||
const n = 64
|
|
||||||
cases := map[string][]flowKeyPair{
|
|
||||||
"sameFlow": make([]flowKeyPair, n),
|
|
||||||
"sportDiffers": make([]flowKeyPair, n),
|
|
||||||
"dstDiffers": make([]flowKeyPair, n),
|
|
||||||
"allDiffer": make([]flowKeyPair, n),
|
|
||||||
}
|
|
||||||
for i := range n {
|
|
||||||
base := makeFlowKey(0x0a000001, 0x0a000002, 40000, 443)
|
|
||||||
cases["sameFlow"][i] = flowKeyPair{a: base, b: base}
|
|
||||||
cases["sportDiffers"][i] = flowKeyPair{
|
|
||||||
a: base,
|
|
||||||
b: makeFlowKey(0x0a000001, 0x0a000002, uint16(40001+i), 443),
|
|
||||||
}
|
|
||||||
cases["dstDiffers"][i] = flowKeyPair{
|
|
||||||
a: base,
|
|
||||||
b: makeFlowKey(0x0a000001, uint32(0x0a000002+i+1), 40000, 443),
|
|
||||||
}
|
|
||||||
cases["allDiffer"][i] = flowKeyPair{
|
|
||||||
a: makeFlowKey(uint32(0x0a000001+i), uint32(0x0a000002+i), uint16(40000+i), uint16(80+i)),
|
|
||||||
b: makeFlowKey(uint32(0x0b000001+i), uint32(0x0b000002+i), uint16(50000+i), uint16(443+i)),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return cases
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkFlowKeyCompare measures flowKeyCompare across the workloads
|
|
||||||
// the sort step actually sees. Use this to compare reorderings.
|
|
||||||
func BenchmarkFlowKeyCompare(b *testing.B) {
|
|
||||||
for name, pairs := range flowKeyCases() {
|
|
||||||
b.Run(name, func(b *testing.B) {
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
var sink int
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
p := pairs[i&(len(pairs)-1)]
|
|
||||||
sink += flowKeyCompare(p.a, p.b)
|
|
||||||
}
|
|
||||||
runtime.KeepAlive(sink)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,60 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net/netip"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
)
|
|
||||||
|
|
||||||
const SendBatchCap = 128
|
|
||||||
|
|
||||||
// batchWriter is the minimal subset of udp.Conn needed by SendBatch to flush.
|
|
||||||
type batchWriter interface {
|
|
||||||
WriteBatch(bufs [][]byte, addrs []netip.AddrPort, outerECNs []byte) error
|
|
||||||
}
|
|
||||||
|
|
||||||
// SendBatch accumulates encrypted UDP packets and flushes them via WriteBatch.
|
|
||||||
// One SendBatch is owned by each listenIn goroutine; no locking is needed.
|
|
||||||
// Slot bytes are borrowed from the injected Arena and remain valid until
|
|
||||||
// Flush, which Resets the arena.
|
|
||||||
type SendBatch struct {
|
|
||||||
out batchWriter
|
|
||||||
bufs [][]byte
|
|
||||||
dsts []netip.AddrPort
|
|
||||||
ecns []byte
|
|
||||||
arena *util.Arena
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewSendBatch makes a SendBatch with batchCap slots backed by arena.
|
|
||||||
func NewSendBatch(out batchWriter, batchCap int, arena *util.Arena) *SendBatch {
|
|
||||||
return &SendBatch{
|
|
||||||
out: out,
|
|
||||||
bufs: make([][]byte, 0, batchCap),
|
|
||||||
dsts: make([]netip.AddrPort, 0, batchCap),
|
|
||||||
ecns: make([]byte, 0, batchCap),
|
|
||||||
arena: arena,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (b *SendBatch) Reserve(sz int) []byte {
|
|
||||||
return b.arena.Reserve(sz)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (b *SendBatch) Commit(pkt []byte, dst netip.AddrPort, outerECN byte) {
|
|
||||||
b.bufs = append(b.bufs, pkt)
|
|
||||||
b.dsts = append(b.dsts, dst)
|
|
||||||
b.ecns = append(b.ecns, outerECN)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (b *SendBatch) Flush() error {
|
|
||||||
var err error
|
|
||||||
if len(b.bufs) > 0 {
|
|
||||||
err = b.out.WriteBatch(b.bufs, b.dsts, b.ecns)
|
|
||||||
}
|
|
||||||
clear(b.bufs)
|
|
||||||
b.bufs = b.bufs[:0]
|
|
||||||
b.dsts = b.dsts[:0]
|
|
||||||
b.ecns = b.ecns[:0]
|
|
||||||
b.arena.Reset()
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
@@ -1,126 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net/netip"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
)
|
|
||||||
|
|
||||||
type fakeBatchWriter struct {
|
|
||||||
bufs [][]byte
|
|
||||||
addrs []netip.AddrPort
|
|
||||||
ecns []byte
|
|
||||||
}
|
|
||||||
|
|
||||||
func (w *fakeBatchWriter) WriteBatch(bufs [][]byte, addrs []netip.AddrPort, ecns []byte) error {
|
|
||||||
// Snapshot — SendBatch.Flush nils its slot pointers right after WriteBatch
|
|
||||||
// returns, so tests must capture data before that happens.
|
|
||||||
w.bufs = make([][]byte, len(bufs))
|
|
||||||
for i, b := range bufs {
|
|
||||||
cp := make([]byte, len(b))
|
|
||||||
copy(cp, b)
|
|
||||||
w.bufs[i] = cp
|
|
||||||
}
|
|
||||||
w.addrs = append(w.addrs[:0], addrs...)
|
|
||||||
w.ecns = append(w.ecns[:0], ecns...)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSendBatchReserveCommitFlush(t *testing.T) {
|
|
||||||
fw := &fakeBatchWriter{}
|
|
||||||
b := NewSendBatch(fw, 4, util.NewArena(32))
|
|
||||||
|
|
||||||
ap := netip.MustParseAddrPort("10.0.0.1:4242")
|
|
||||||
for i := 0; i < 4; i++ {
|
|
||||||
slot := b.Reserve(32)
|
|
||||||
if cap(slot) != 32 {
|
|
||||||
t.Fatalf("slot %d: cap=%d want 32", i, cap(slot))
|
|
||||||
}
|
|
||||||
pkt := append(slot[:0], byte(i), byte(i+1), byte(i+2))
|
|
||||||
b.Commit(pkt, ap, 0)
|
|
||||||
}
|
|
||||||
if err := b.Flush(); err != nil {
|
|
||||||
t.Fatalf("Flush: %v", err)
|
|
||||||
}
|
|
||||||
if len(fw.bufs) != 4 {
|
|
||||||
t.Fatalf("WriteBatch got %d bufs want 4", len(fw.bufs))
|
|
||||||
}
|
|
||||||
for i, buf := range fw.bufs {
|
|
||||||
if len(buf) != 3 || buf[0] != byte(i) {
|
|
||||||
t.Errorf("buf %d: %x", i, buf)
|
|
||||||
}
|
|
||||||
if fw.addrs[i] != ap {
|
|
||||||
t.Errorf("addr %d: got %v want %v", i, fw.addrs[i], ap)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Flush again with nothing committed — should be a no-op.
|
|
||||||
fw.bufs = nil
|
|
||||||
if err := b.Flush(); err != nil {
|
|
||||||
t.Fatalf("empty Flush: %v", err)
|
|
||||||
}
|
|
||||||
if fw.bufs != nil {
|
|
||||||
t.Fatalf("empty Flush triggered WriteBatch")
|
|
||||||
}
|
|
||||||
|
|
||||||
// Reuse after Flush.
|
|
||||||
slot := b.Reserve(32)
|
|
||||||
if cap(slot) != 32 {
|
|
||||||
t.Fatalf("after Flush Reserve wrong cap: %d", cap(slot))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSendBatchSlotsDoNotOverlap(t *testing.T) {
|
|
||||||
fw := &fakeBatchWriter{}
|
|
||||||
b := NewSendBatch(fw, 3, util.NewArena(8))
|
|
||||||
ap := netip.MustParseAddrPort("10.0.0.1:80")
|
|
||||||
|
|
||||||
for i := 0; i < 3; i++ {
|
|
||||||
s := b.Reserve(8)
|
|
||||||
pkt := append(s[:0], byte(0xA0+i), byte(0xB0+i))
|
|
||||||
b.Commit(pkt, ap, 0)
|
|
||||||
}
|
|
||||||
if err := b.Flush(); err != nil {
|
|
||||||
t.Fatalf("Flush: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
for i, buf := range fw.bufs {
|
|
||||||
if buf[0] != byte(0xA0+i) || buf[1] != byte(0xB0+i) {
|
|
||||||
t.Errorf("slot %d corrupted: %x", i, buf)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSendBatchGrowPreservesCommitted(t *testing.T) {
|
|
||||||
fw := &fakeBatchWriter{}
|
|
||||||
// Tiny initial backing forces a grow on the second Reserve.
|
|
||||||
b := NewSendBatch(fw, 1, util.NewArena(4))
|
|
||||||
ap := netip.MustParseAddrPort("10.0.0.1:80")
|
|
||||||
|
|
||||||
s1 := b.Reserve(4)
|
|
||||||
pkt1 := append(s1[:0], 0x11, 0x22, 0x33, 0x44)
|
|
||||||
b.Commit(pkt1, ap, 0)
|
|
||||||
|
|
||||||
s2 := b.Reserve(8) // exceeds remaining cap, triggers grow
|
|
||||||
pkt2 := append(s2[:0], 0xA, 0xB, 0xC, 0xD, 0xE)
|
|
||||||
b.Commit(pkt2, ap, 0)
|
|
||||||
|
|
||||||
// pkt1 must still be intact even though backing reallocated.
|
|
||||||
if pkt1[0] != 0x11 || pkt1[3] != 0x44 {
|
|
||||||
t.Fatalf("first packet corrupted by grow: %x", pkt1)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := b.Flush(); err != nil {
|
|
||||||
t.Fatalf("Flush: %v", err)
|
|
||||||
}
|
|
||||||
if len(fw.bufs) != 2 {
|
|
||||||
t.Fatalf("got %d bufs want 2", len(fw.bufs))
|
|
||||||
}
|
|
||||||
if fw.bufs[0][0] != 0x11 || fw.bufs[0][3] != 0x44 {
|
|
||||||
t.Errorf("first packet on the wire: %x", fw.bufs[0])
|
|
||||||
}
|
|
||||||
if fw.bufs[1][0] != 0xA || fw.bufs[1][4] != 0xE {
|
|
||||||
t.Errorf("second packet on the wire: %x", fw.bufs[1])
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,339 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"io"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
|
||||||
|
|
||||||
// ipProtoUDP is the IANA protocol number for UDP.
|
|
||||||
const ipProtoUDP = 17
|
|
||||||
|
|
||||||
// udpCoalesceBufSize caps total bytes per UDP superpacket. Mirrors the
|
|
||||||
// kernel's gso_max_size; payloads beyond this are emitted as-is.
|
|
||||||
const udpCoalesceBufSize = 65535
|
|
||||||
|
|
||||||
// udpCoalesceMaxSegs caps how many segments we'll coalesce. Kernel UDP-GSO
|
|
||||||
// accepts up to 64 segments per skb (UDP_MAX_SEGMENTS); stay under that.
|
|
||||||
const udpCoalesceMaxSegs = 64
|
|
||||||
|
|
||||||
// udpCoalesceHdrCap is the scratch space we copy a seed's IP+UDP header
|
|
||||||
// into. IPv6 (40) + UDP (8) = 48; round up for safety.
|
|
||||||
const udpCoalesceHdrCap = 64
|
|
||||||
|
|
||||||
// udpSlot is one entry in the UDPCoalescer's ordered event queue. Same
|
|
||||||
// passthrough-vs-coalesced shape as the TCP coalescer's slot, but no
|
|
||||||
// seq/PSH/CWR bookkeeping — UDP segments only need 5-tuple + length
|
|
||||||
// matching to coalesce.
|
|
||||||
type udpSlot struct {
|
|
||||||
passthrough bool
|
|
||||||
rawPkt []byte // borrowed when passthrough
|
|
||||||
|
|
||||||
fk flowKey
|
|
||||||
hdrBuf [udpCoalesceHdrCap]byte
|
|
||||||
hdrLen int
|
|
||||||
ipHdrLen int
|
|
||||||
isV6 bool
|
|
||||||
gsoSize int // per-segment UDP payload length
|
|
||||||
numSeg int
|
|
||||||
totalPay int
|
|
||||||
// sealed closes the chain: set when a sub-gsoSize segment is appended
|
|
||||||
// (kernel UDP-GSO requires every segment but the last to be exactly
|
|
||||||
// gsoSize) or when limits are hit. No further appends after.
|
|
||||||
sealed bool
|
|
||||||
payIovs [][]byte
|
|
||||||
}
|
|
||||||
|
|
||||||
// UDPCoalescer accumulates adjacent in-flow UDP datagrams across multiple
|
|
||||||
// concurrent flows and emits each flow's run as a single GSO_UDP_L4
|
|
||||||
// superpacket via tio.GSOWriter. Falls back to per-packet writes when the
|
|
||||||
// underlying writer doesn't support USO.
|
|
||||||
//
|
|
||||||
// All output — coalesced or not — is deferred until Flush so per-flow
|
|
||||||
// arrival order is preserved on the wire. Cross-flow order is NOT preserved
|
|
||||||
// across the TCP/UDP/passthrough split when this coalescer runs alongside
|
|
||||||
// others — see multi_coalesce.go. Per-flow order is preserved because a
|
|
||||||
// single 5-tuple only ever lands in one lane and each lane preserves its
|
|
||||||
// own slot order.
|
|
||||||
//
|
|
||||||
// Owns no locks; one coalescer per TUN write queue.
|
|
||||||
type UDPCoalescer struct {
|
|
||||||
plainW io.Writer
|
|
||||||
gsoW tio.GSOWriter // nil when the queue can't accept GSO_UDP_L4
|
|
||||||
|
|
||||||
slots []*udpSlot
|
|
||||||
openSlots map[flowKey]*udpSlot
|
|
||||||
pool []*udpSlot
|
|
||||||
|
|
||||||
// arena is injected; see TCPCoalescer.arena for the contract.
|
|
||||||
arena *util.Arena
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewUDPCoalescer wraps w. The caller is responsible for only constructing
|
|
||||||
// this when the underlying Queue's Capabilities advertise USO; otherwise
|
|
||||||
// the kernel may reject GSO_UDP_L4 writes. If w does not implement
|
|
||||||
// tio.GSOWriter at all (single-packet Queue), the coalescer degrades to
|
|
||||||
// plain Writes — same defensive shape as the TCP coalescer.
|
|
||||||
func NewUDPCoalescer(w tio.Queue, arena *util.Arena) *UDPCoalescer {
|
|
||||||
c := &UDPCoalescer{
|
|
||||||
plainW: w,
|
|
||||||
slots: make([]*udpSlot, 0, initialSlots),
|
|
||||||
openSlots: make(map[flowKey]*udpSlot, initialSlots),
|
|
||||||
pool: make([]*udpSlot, 0, initialSlots),
|
|
||||||
arena: arena,
|
|
||||||
}
|
|
||||||
if gw, ok := tio.SupportsGSO(w, wire.GSOProtoUDP); ok {
|
|
||||||
c.gsoW = gw
|
|
||||||
}
|
|
||||||
return c
|
|
||||||
}
|
|
||||||
|
|
||||||
// parsedUDP holds the fields extracted from a single parse so later steps
|
|
||||||
// (admission, slot lookup, canAppend) don't re-walk the header.
|
|
||||||
type parsedUDP struct {
|
|
||||||
fk flowKey
|
|
||||||
ipHdrLen int
|
|
||||||
hdrLen int // ipHdrLen + 8
|
|
||||||
payLen int
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseUDP extracts the flow key and IP/UDP offsets for a UDP packet.
|
|
||||||
// Returns ok=false for non-UDP, malformed, or unsupported header shapes
|
|
||||||
// (IPv4 with options/fragmentation, IPv6 with extension headers).
|
|
||||||
func parseUDP(pkt []byte) (parsedUDP, bool) {
|
|
||||||
var p parsedUDP
|
|
||||||
ip, ok := parseIPPrologue(pkt, ipProtoUDP)
|
|
||||||
if !ok {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
pkt = ip.pkt
|
|
||||||
p.fk = ip.fk
|
|
||||||
p.ipHdrLen = ip.ipHdrLen
|
|
||||||
|
|
||||||
if len(pkt) < p.ipHdrLen+8 {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
p.hdrLen = p.ipHdrLen + 8
|
|
||||||
// UDP `length` field: must equal IP-derived length-of-UDP-header-plus-payload.
|
|
||||||
udpLen := int(binary.BigEndian.Uint16(pkt[p.ipHdrLen+4 : p.ipHdrLen+6]))
|
|
||||||
if udpLen < 8 || udpLen > len(pkt)-p.ipHdrLen {
|
|
||||||
return p, false
|
|
||||||
}
|
|
||||||
p.payLen = udpLen - 8
|
|
||||||
p.fk.sport = binary.BigEndian.Uint16(pkt[p.ipHdrLen : p.ipHdrLen+2])
|
|
||||||
p.fk.dport = binary.BigEndian.Uint16(pkt[p.ipHdrLen+2 : p.ipHdrLen+4])
|
|
||||||
return p, true
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *UDPCoalescer) Reserve(sz int) []byte {
|
|
||||||
return c.arena.Reserve(sz)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Commit borrows pkt. The caller must keep pkt valid until the next Flush.
|
|
||||||
func (c *UDPCoalescer) Commit(pkt []byte) error {
|
|
||||||
if c.gsoW == nil {
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
info, ok := parseUDP(pkt)
|
|
||||||
if !ok {
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
return c.commitParsed(pkt, info)
|
|
||||||
}
|
|
||||||
|
|
||||||
// commitParsed is the post-parse half of Commit. The caller must have
|
|
||||||
// already verified parseUDP succeeded. Used by MultiCoalescer.Commit to
|
|
||||||
// avoid re-walking the IP/UDP header.
|
|
||||||
func (c *UDPCoalescer) commitParsed(pkt []byte, info parsedUDP) error {
|
|
||||||
if c.gsoW == nil {
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if open := c.openSlots[info.fk]; open != nil {
|
|
||||||
if c.canAppend(open, pkt, info) {
|
|
||||||
c.appendPayload(open, pkt, info)
|
|
||||||
if open.sealed {
|
|
||||||
delete(c.openSlots, info.fk)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
// Can't extend — seal it and fall through to seed a fresh slot.
|
|
||||||
delete(c.openSlots, info.fk)
|
|
||||||
}
|
|
||||||
c.seed(pkt, info)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *UDPCoalescer) Flush() error {
|
|
||||||
var first error
|
|
||||||
for _, s := range c.slots {
|
|
||||||
var err error
|
|
||||||
if s.passthrough {
|
|
||||||
_, err = c.plainW.Write(s.rawPkt)
|
|
||||||
} else {
|
|
||||||
err = c.flushSlot(s)
|
|
||||||
}
|
|
||||||
if err != nil && first == nil {
|
|
||||||
first = err
|
|
||||||
}
|
|
||||||
c.release(s)
|
|
||||||
}
|
|
||||||
clear(c.slots)
|
|
||||||
c.slots = c.slots[:0]
|
|
||||||
clear(c.openSlots)
|
|
||||||
c.arena.Reset()
|
|
||||||
return first
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *UDPCoalescer) addPassthrough(pkt []byte) {
|
|
||||||
s := c.take()
|
|
||||||
s.passthrough = true
|
|
||||||
s.rawPkt = pkt
|
|
||||||
c.slots = append(c.slots, s)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *UDPCoalescer) seed(pkt []byte, info parsedUDP) {
|
|
||||||
if info.hdrLen > udpCoalesceHdrCap || info.hdrLen+info.payLen > udpCoalesceBufSize {
|
|
||||||
c.addPassthrough(pkt)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
s := c.take()
|
|
||||||
s.passthrough = false
|
|
||||||
s.rawPkt = nil
|
|
||||||
copy(s.hdrBuf[:], pkt[:info.hdrLen])
|
|
||||||
s.hdrLen = info.hdrLen
|
|
||||||
s.ipHdrLen = info.ipHdrLen
|
|
||||||
s.isV6 = info.fk.isV6
|
|
||||||
s.fk = info.fk
|
|
||||||
s.gsoSize = info.payLen
|
|
||||||
s.numSeg = 1
|
|
||||||
s.totalPay = info.payLen
|
|
||||||
s.sealed = false
|
|
||||||
s.payIovs = append(s.payIovs[:0], pkt[info.hdrLen:info.hdrLen+info.payLen])
|
|
||||||
c.slots = append(c.slots, s)
|
|
||||||
c.openSlots[info.fk] = s
|
|
||||||
}
|
|
||||||
|
|
||||||
// canAppend reports whether info's packet extends the slot's seed.
|
|
||||||
// Kernel UDP-GSO requires every segment except possibly the last to be
|
|
||||||
// exactly gsoSize, and the last may be shorter (≤ gsoSize).
|
|
||||||
func (c *UDPCoalescer) canAppend(s *udpSlot, pkt []byte, info parsedUDP) bool {
|
|
||||||
if s.sealed {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if info.hdrLen != s.hdrLen {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if s.numSeg >= udpCoalesceMaxSegs {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if info.payLen > s.gsoSize {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if s.hdrLen+s.totalPay+info.payLen > udpCoalesceBufSize {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !udpHeadersMatch(s.hdrBuf[:s.hdrLen], pkt[:info.hdrLen], s.isV6, s.ipHdrLen) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *UDPCoalescer) appendPayload(s *udpSlot, pkt []byte, info parsedUDP) {
|
|
||||||
s.payIovs = append(s.payIovs, pkt[info.hdrLen:info.hdrLen+info.payLen])
|
|
||||||
s.numSeg++
|
|
||||||
s.totalPay += info.payLen
|
|
||||||
// Merge IP-level CE marks into the seed (same trick TCP coalescer uses).
|
|
||||||
mergeECNIntoSeed(s.hdrBuf[:s.ipHdrLen], pkt[:s.ipHdrLen], s.isV6)
|
|
||||||
if info.payLen < s.gsoSize {
|
|
||||||
// Last-segment-can-be-shorter: this seals the chain.
|
|
||||||
s.sealed = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *UDPCoalescer) take() *udpSlot {
|
|
||||||
if n := len(c.pool); n > 0 {
|
|
||||||
s := c.pool[n-1]
|
|
||||||
c.pool[n-1] = nil
|
|
||||||
c.pool = c.pool[:n-1]
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
return &udpSlot{}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *UDPCoalescer) release(s *udpSlot) {
|
|
||||||
s.passthrough = false
|
|
||||||
s.rawPkt = nil
|
|
||||||
clear(s.payIovs)
|
|
||||||
s.payIovs = s.payIovs[:0]
|
|
||||||
s.numSeg = 0
|
|
||||||
s.totalPay = 0
|
|
||||||
s.sealed = false
|
|
||||||
c.pool = append(c.pool, s)
|
|
||||||
}
|
|
||||||
|
|
||||||
// flushSlot patches the IP header total length / IPv6 payload length and
|
|
||||||
// the UDP length to the *total* across all coalesced segments, then seeds
|
|
||||||
// the UDP checksum field with the pseudo-header partial (single-fold, not
|
|
||||||
// inverted) per virtio NEEDS_CSUM. The kernel's ip_rcv_core (v4) and
|
|
||||||
// ip6_rcv_core (v6) trim the skb to those length fields, so per-segment
|
|
||||||
// values would silently drop everything but the first segment. The kernel
|
|
||||||
// then walks each segment in __udp_gso_segment, recomputing per-segment
|
|
||||||
// uh->len / iph->tot_len / IPv6 plen and adjusting the checksum via
|
|
||||||
// `check = csum16_add(csum16_sub(uh->check, uh->len), newlen)` — meaning
|
|
||||||
// our seed's uh->check must be consistent with the seed's uh->len, which
|
|
||||||
// is what passing the total to both pseudoSum and the UDP length field
|
|
||||||
// guarantees.
|
|
||||||
func (c *UDPCoalescer) flushSlot(s *udpSlot) error {
|
|
||||||
hdr := s.hdrBuf[:s.hdrLen]
|
|
||||||
total := s.hdrLen + s.totalPay // full IP+UDP+all_payloads bytes
|
|
||||||
l4Len := total - s.ipHdrLen // total UDP (8 + sum of payloads)
|
|
||||||
|
|
||||||
if s.isV6 {
|
|
||||||
binary.BigEndian.PutUint16(hdr[4:6], uint16(l4Len))
|
|
||||||
} else {
|
|
||||||
binary.BigEndian.PutUint16(hdr[2:4], uint16(total))
|
|
||||||
hdr[10] = 0
|
|
||||||
hdr[11] = 0
|
|
||||||
binary.BigEndian.PutUint16(hdr[10:12], ipv4HdrChecksum(hdr[:s.ipHdrLen]))
|
|
||||||
}
|
|
||||||
|
|
||||||
// UDP length field (offset 4 inside the UDP header) = total UDP size.
|
|
||||||
binary.BigEndian.PutUint16(hdr[s.ipHdrLen+4:s.ipHdrLen+6], uint16(l4Len))
|
|
||||||
|
|
||||||
var psum uint32
|
|
||||||
if s.isV6 {
|
|
||||||
psum = pseudoSumIPv6(hdr[8:24], hdr[24:40], ipProtoUDP, l4Len)
|
|
||||||
} else {
|
|
||||||
psum = pseudoSumIPv4(hdr[12:16], hdr[16:20], ipProtoUDP, l4Len)
|
|
||||||
}
|
|
||||||
udpCsumOff := s.ipHdrLen + 6
|
|
||||||
binary.BigEndian.PutUint16(hdr[udpCsumOff:udpCsumOff+2], foldOnceNoInvert(psum))
|
|
||||||
|
|
||||||
return c.gsoW.WriteGSO(hdr[:s.ipHdrLen], hdr[s.ipHdrLen:], s.payIovs, wire.GSOProtoUDP)
|
|
||||||
}
|
|
||||||
|
|
||||||
// udpHeadersMatch compares two IP+UDP header prefixes for byte-equality on
|
|
||||||
// every field that must be identical across coalesced segments. Length
|
|
||||||
// fields and the ECN bits in IP TOS/TC are masked out — appendPayload
|
|
||||||
// merges CE into the seed; flushSlot rewrites lengths.
|
|
||||||
func udpHeadersMatch(a, b []byte, isV6 bool, ipHdrLen int) bool {
|
|
||||||
if len(a) != len(b) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if !ipHeadersMatch(a, b, isV6) {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
// UDP: compare sport+dport ([0:4]). Skip length [4:6] and checksum [6:8] —
|
|
||||||
// length varies (we rewrite at flush) and the checksum will be redone.
|
|
||||||
udp := ipHdrLen
|
|
||||||
if a[udp] != b[udp] || a[udp+1] != b[udp+1] || a[udp+2] != b[udp+2] || a[udp+3] != b[udp+3] {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
@@ -1,385 +0,0 @@
|
|||||||
package batch
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/util"
|
|
||||||
)
|
|
||||||
|
|
||||||
// buildUDPv4 builds a minimal IPv4+UDP packet with the given payload and ports.
|
|
||||||
func buildUDPv4(sport, dport uint16, payload []byte) []byte {
|
|
||||||
const ipHdrLen = 20
|
|
||||||
const udpHdrLen = 8
|
|
||||||
total := ipHdrLen + udpHdrLen + len(payload)
|
|
||||||
pkt := make([]byte, total)
|
|
||||||
|
|
||||||
pkt[0] = 0x45
|
|
||||||
pkt[1] = 0x00
|
|
||||||
binary.BigEndian.PutUint16(pkt[2:4], uint16(total))
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], 0)
|
|
||||||
binary.BigEndian.PutUint16(pkt[6:8], 0x4000)
|
|
||||||
pkt[8] = 64
|
|
||||||
pkt[9] = ipProtoUDP
|
|
||||||
copy(pkt[12:16], []byte{10, 0, 0, 1})
|
|
||||||
copy(pkt[16:20], []byte{10, 0, 0, 2})
|
|
||||||
|
|
||||||
binary.BigEndian.PutUint16(pkt[20:22], sport)
|
|
||||||
binary.BigEndian.PutUint16(pkt[22:24], dport)
|
|
||||||
binary.BigEndian.PutUint16(pkt[24:26], uint16(udpHdrLen+len(payload)))
|
|
||||||
binary.BigEndian.PutUint16(pkt[26:28], 0)
|
|
||||||
|
|
||||||
copy(pkt[28:], payload)
|
|
||||||
return pkt
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildUDPv6 builds a minimal IPv6+UDP packet.
|
|
||||||
func buildUDPv6(sport, dport uint16, payload []byte) []byte {
|
|
||||||
const ipHdrLen = 40
|
|
||||||
const udpHdrLen = 8
|
|
||||||
total := ipHdrLen + udpHdrLen + len(payload)
|
|
||||||
pkt := make([]byte, total)
|
|
||||||
|
|
||||||
pkt[0] = 0x60
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], uint16(udpHdrLen+len(payload)))
|
|
||||||
pkt[6] = ipProtoUDP
|
|
||||||
pkt[7] = 64
|
|
||||||
pkt[8] = 0xfe
|
|
||||||
pkt[9] = 0x80
|
|
||||||
pkt[23] = 1
|
|
||||||
pkt[24] = 0xfe
|
|
||||||
pkt[25] = 0x80
|
|
||||||
pkt[39] = 2
|
|
||||||
|
|
||||||
binary.BigEndian.PutUint16(pkt[40:42], sport)
|
|
||||||
binary.BigEndian.PutUint16(pkt[42:44], dport)
|
|
||||||
binary.BigEndian.PutUint16(pkt[44:46], uint16(udpHdrLen+len(payload)))
|
|
||||||
binary.BigEndian.PutUint16(pkt[46:48], 0)
|
|
||||||
|
|
||||||
copy(pkt[48:], payload)
|
|
||||||
return pkt
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestUDPCoalescerPassthroughWhenGSOUnavailable(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: false}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pkt := buildUDPv4(1000, 53, make([]byte, 100))
|
|
||||||
if err := c.Commit(pkt); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.writes) != 0 || len(w.gsoWrites) != 0 {
|
|
||||||
t.Fatalf("no Add-time writes: writes=%d gso=%d", len(w.writes), len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.writes) != 1 || len(w.gsoWrites) != 0 {
|
|
||||||
t.Fatalf("want single plain write, got writes=%d gso=%d", len(w.writes), len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestUDPCoalescerNonUDPPassthrough(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
// ICMP packet
|
|
||||||
pkt := make([]byte, 28)
|
|
||||||
pkt[0] = 0x45
|
|
||||||
binary.BigEndian.PutUint16(pkt[2:4], 28)
|
|
||||||
pkt[9] = 1
|
|
||||||
copy(pkt[12:16], []byte{10, 0, 0, 1})
|
|
||||||
copy(pkt[16:20], []byte{10, 0, 0, 2})
|
|
||||||
if err := c.Commit(pkt); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.writes) != 1 || len(w.gsoWrites) != 0 {
|
|
||||||
t.Fatalf("ICMP must pass through unchanged: writes=%d gso=%d", len(w.writes), len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestUDPCoalescerSeedThenFlushAlone(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pkt := buildUDPv4(1000, 53, make([]byte, 800))
|
|
||||||
if err := c.Commit(pkt); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
// Single-segment flush goes through WriteGSO; the writer infers GSO_NONE
|
|
||||||
// from len(pays)==1 and the kernel fills in the UDP csum (NEEDS_CSUM).
|
|
||||||
if len(w.gsoWrites) != 1 || len(w.writes) != 0 {
|
|
||||||
t.Fatalf("single-seg flush: writes=%d gso=%d", len(w.writes), len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestUDPCoalescerCoalescesEqualSized(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pay := make([]byte, 1200)
|
|
||||||
for i := 0; i < 3; i++ {
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 1 {
|
|
||||||
t.Fatalf("want 1 gso write, got %d (plain=%d)", len(w.gsoWrites), len(w.writes))
|
|
||||||
}
|
|
||||||
g := w.gsoWrites[0]
|
|
||||||
if g.gsoSize != 1200 {
|
|
||||||
t.Errorf("gsoSize=%d want 1200", g.gsoSize)
|
|
||||||
}
|
|
||||||
if len(g.pays) != 3 {
|
|
||||||
t.Errorf("pay count=%d want 3", len(g.pays))
|
|
||||||
}
|
|
||||||
if g.csumStart != 20 {
|
|
||||||
t.Errorf("csumStart=%d want 20", g.csumStart)
|
|
||||||
}
|
|
||||||
// IP totalLen and UDP length must be the TOTAL across all segments —
|
|
||||||
// the kernel's ip_rcv_core trims skbs to iph->tot_len, so a per-segment
|
|
||||||
// value would silently drop everything but the first segment. Total =
|
|
||||||
// IP(20) + UDP(8) + 3*1200 = 3628.
|
|
||||||
gotTotalLen := binary.BigEndian.Uint16(g.hdr[2:4])
|
|
||||||
if gotTotalLen != 3628 {
|
|
||||||
t.Errorf("ipv4 total_len=%d want 3628 (must be total across segments)", gotTotalLen)
|
|
||||||
}
|
|
||||||
gotUDPLen := binary.BigEndian.Uint16(g.hdr[20+4 : 20+6])
|
|
||||||
if gotUDPLen != 8+3*1200 {
|
|
||||||
t.Errorf("udp len=%d want %d", gotUDPLen, 8+3*1200)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Last segment may be shorter, sealing the chain.
|
|
||||||
func TestUDPCoalescerShortLastSegmentSeals(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
full := make([]byte, 1200)
|
|
||||||
tail := make([]byte, 600)
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, full)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, full)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, tail)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
// A 4th packet, even same-sized, must NOT join — chain is sealed.
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, full)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 2 {
|
|
||||||
t.Fatalf("want 2 gso writes (sealed + new seed), got %d", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites[0].pays) != 3 {
|
|
||||||
t.Errorf("first super: want 3 pays, got %d", len(w.gsoWrites[0].pays))
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites[1].pays) != 1 {
|
|
||||||
t.Errorf("second super: want 1 pay (re-seed), got %d", len(w.gsoWrites[1].pays))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// A larger-than-gsoSize packet cannot extend the slot — it reseeds.
|
|
||||||
func TestUDPCoalescerLargerThanSeedReseeds(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, make([]byte, 800))); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, make([]byte, 1200))); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 2 {
|
|
||||||
t.Fatalf("want 2 separate seeds, got %d", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Different 5-tuples must not coalesce.
|
|
||||||
func TestUDPCoalescerDifferentFlowsKeepSeparate(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pay := make([]byte, 800)
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(buildUDPv4(2000, 53, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(buildUDPv4(2000, 53, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
// Two flows × 2 datagrams each = 2 superpackets of 2 segments.
|
|
||||||
if len(w.gsoWrites) != 2 {
|
|
||||||
t.Fatalf("want 2 gso writes (one per flow), got %d", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
for i, g := range w.gsoWrites {
|
|
||||||
if len(g.pays) != 2 {
|
|
||||||
t.Errorf("super %d: want 2 pays, got %d", i, len(g.pays))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Caps at udpCoalesceMaxSegs.
|
|
||||||
func TestUDPCoalescerCapsAtMaxSegs(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pay := make([]byte, 100)
|
|
||||||
for i := 0; i < udpCoalesceMaxSegs+5; i++ {
|
|
||||||
if err := c.Commit(buildUDPv4(1000, 53, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
// First superpacket holds udpCoalesceMaxSegs segments; the spillover
|
|
||||||
// reseeds a new one.
|
|
||||||
if len(w.gsoWrites) != 2 {
|
|
||||||
t.Fatalf("want 2 gso writes (cap then reseed), got %d", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites[0].pays) != udpCoalesceMaxSegs {
|
|
||||||
t.Errorf("first super: pays=%d want %d", len(w.gsoWrites[0].pays), udpCoalesceMaxSegs)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites[1].pays) != 5 {
|
|
||||||
t.Errorf("second super: pays=%d want 5", len(w.gsoWrites[1].pays))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// CE marks on appended segments must be merged into the seed's IP TOS.
|
|
||||||
func TestUDPCoalescerMergesCEMark(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pay := make([]byte, 800)
|
|
||||||
pkt0 := buildUDPv4(1000, 53, pay) // ECN=00
|
|
||||||
pkt1 := buildUDPv4(1000, 53, pay)
|
|
||||||
pkt1[1] = 0x03 // CE
|
|
||||||
pkt2 := buildUDPv4(1000, 53, pay)
|
|
||||||
if err := c.Commit(pkt0); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(pkt1); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(pkt2); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 1 {
|
|
||||||
t.Fatalf("want 1 merged gso write, got %d (plain=%d)", len(w.gsoWrites), len(w.writes))
|
|
||||||
}
|
|
||||||
if w.gsoWrites[0].hdr[1]&0x03 != 0x03 {
|
|
||||||
t.Errorf("CE not merged into seed (tos=%#x)", w.gsoWrites[0].hdr[1])
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// IPv6 path: same flow, equal-sized → coalesced.
|
|
||||||
func TestUDPCoalescerIPv6Coalesces(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pay := make([]byte, 1200)
|
|
||||||
for i := 0; i < 3; i++ {
|
|
||||||
if err := c.Commit(buildUDPv6(1000, 53, pay)); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 1 {
|
|
||||||
t.Fatalf("want 1 gso write, got %d", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
g := w.gsoWrites[0]
|
|
||||||
if !g.isV6 {
|
|
||||||
t.Errorf("expected v6 write")
|
|
||||||
}
|
|
||||||
if g.csumStart != 40 {
|
|
||||||
t.Errorf("csumStart=%d want 40", g.csumStart)
|
|
||||||
}
|
|
||||||
// IPv6 payload_len and UDP length must be TOTAL — kernel's
|
|
||||||
// ip6_rcv_core trims to payload_len + ipv6 hdr size. Total UDP = 8 +
|
|
||||||
// 3*1200 = 3608.
|
|
||||||
gotPlen := binary.BigEndian.Uint16(g.hdr[4:6])
|
|
||||||
if gotPlen != 8+3*1200 {
|
|
||||||
t.Errorf("ipv6 payload_len=%d want %d (must be total)", gotPlen, 8+3*1200)
|
|
||||||
}
|
|
||||||
gotUDPLen := binary.BigEndian.Uint16(g.hdr[40+4 : 40+6])
|
|
||||||
if gotUDPLen != 8+3*1200 {
|
|
||||||
t.Errorf("udp len=%d want %d", gotUDPLen, 8+3*1200)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// DSCP differences must reseed (headers don't match outside ECN).
|
|
||||||
func TestUDPCoalescerDSCPMismatchReseeds(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pay := make([]byte, 800)
|
|
||||||
pkt0 := buildUDPv4(1000, 53, pay)
|
|
||||||
pkt1 := buildUDPv4(1000, 53, pay)
|
|
||||||
pkt1[1] = 0xb8 // EF DSCP, ECN=0
|
|
||||||
if err := c.Commit(pkt0); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Commit(pkt1); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.gsoWrites) != 2 {
|
|
||||||
t.Fatalf("want 2 separate seeds (different DSCP), got %d", len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Fragmented IPv4 must not be coalesced.
|
|
||||||
func TestUDPCoalescerFragmentedIPv4PassesThrough(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pkt := buildUDPv4(1000, 53, make([]byte, 200))
|
|
||||||
binary.BigEndian.PutUint16(pkt[6:8], 0x2000) // MF=1
|
|
||||||
if err := c.Commit(pkt); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.writes) != 1 || len(w.gsoWrites) != 0 {
|
|
||||||
t.Fatalf("frag must pass through plain, got writes=%d gso=%d", len(w.writes), len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// IPv4 with options is not admissible (we require IHL=5).
|
|
||||||
func TestUDPCoalescerIPv4WithOptionsPassesThrough(t *testing.T) {
|
|
||||||
w := &fakeTunWriter{gsoEnabled: true}
|
|
||||||
c := NewUDPCoalescer(w, util.NewArena(0))
|
|
||||||
pkt := buildUDPv4(1000, 53, make([]byte, 200))
|
|
||||||
pkt[0] = 0x46 // IHL = 6 (24-byte IPv4 header — has options)
|
|
||||||
if err := c.Commit(pkt); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if err := c.Flush(); err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
if len(w.writes) != 1 || len(w.gsoWrites) != 0 {
|
|
||||||
t.Fatalf("ipv4-with-options must pass through plain, got writes=%d gso=%d", len(w.writes), len(w.gsoWrites))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
package checksum
|
|
||||||
|
|
||||||
import (
|
|
||||||
"golang.org/x/sys/cpu"
|
|
||||||
gvisorchecksum "gvisor.dev/gvisor/pkg/tcpip/checksum"
|
|
||||||
)
|
|
||||||
|
|
||||||
//go:noescape
|
|
||||||
func checksumAVX2(buf []byte, initial uint16) uint16
|
|
||||||
|
|
||||||
var hasAVX2 = cpu.X86.HasAVX2
|
|
||||||
|
|
||||||
// Checksum computes the RFC 1071 ones-complement sum of buf, seeded with
|
|
||||||
// initial. It is a drop-in replacement for gvisor's checksum.Checksum that
|
|
||||||
// dispatches to a hand-written AVX2 routine on amd64 CPUs that support it,
|
|
||||||
// falling back to gvisor's pure-Go implementation otherwise. The result
|
|
||||||
// matches gvisor's bit-for-bit for any buffer length and initial seed.
|
|
||||||
func Checksum(buf []byte, initial uint16) uint16 {
|
|
||||||
if hasAVX2 {
|
|
||||||
return checksumAVX2(buf, initial)
|
|
||||||
}
|
|
||||||
return gvisorchecksum.Checksum(buf, initial)
|
|
||||||
}
|
|
||||||
@@ -1,157 +0,0 @@
|
|||||||
#include "textflag.h"
|
|
||||||
|
|
||||||
// func checksumAVX2(buf []byte, initial uint16) uint16
|
|
||||||
//
|
|
||||||
// Computes the RFC 1071 ones-complement sum of buf, seeded with initial.
|
|
||||||
//
|
|
||||||
// Algorithm: sum the buffer treating it as a stream of uint32s in machine
|
|
||||||
// (little-endian) byte order, accumulating into 64-bit lanes (top 32 bits
|
|
||||||
// hold cross-add carries — at 1 byte / lane / iter we have 32 bits of
|
|
||||||
// headroom which is far more than the 16 KB/64 KB max practical inputs).
|
|
||||||
// At the end we fold to 16 bits and byte-swap once to recover the on-wire
|
|
||||||
// (big-endian) result. RFC 1071 §1.2.B byte-order independence makes this
|
|
||||||
// equivalent to summing as 16-bit big-endian words.
|
|
||||||
//
|
|
||||||
// The ymm accumulators (Y4..Y7) hold 4 uint64 lanes each = 16 parallel
|
|
||||||
// partial sums. The main loop loads 64 bytes per iter as four 16-byte
|
|
||||||
// chunks, zero-extending each chunk's four uint32s into a ymm via
|
|
||||||
// VPMOVZXDQ-from-memory, then VPADDQ into a separate accumulator per
|
|
||||||
// chunk to break the dep chain. After the vector loop the lane sums are
|
|
||||||
// horizontally reduced and merged with a scalar accumulator that handles
|
|
||||||
// the trailing 0..63 bytes plus the (byte-swapped) initial seed.
|
|
||||||
TEXT ·checksumAVX2(SB), NOSPLIT, $0-34
|
|
||||||
MOVQ buf_base+0(FP), SI
|
|
||||||
MOVQ buf_len+8(FP), CX
|
|
||||||
MOVWQZX initial+24(FP), AX
|
|
||||||
|
|
||||||
// Pre-byteswap initial into the LE-summing space so it merges directly
|
|
||||||
// with the rest of the accumulator. The final fold's bswap16 will undo
|
|
||||||
// this and convert the whole result back to BE.
|
|
||||||
XCHGB AH, AL
|
|
||||||
|
|
||||||
CMPQ CX, $32
|
|
||||||
JLT scalar_tail
|
|
||||||
|
|
||||||
VPXOR Y4, Y4, Y4
|
|
||||||
VPXOR Y5, Y5, Y5
|
|
||||||
VPXOR Y6, Y6, Y6
|
|
||||||
VPXOR Y7, Y7, Y7
|
|
||||||
|
|
||||||
CMPQ CX, $64
|
|
||||||
JLT loop32
|
|
||||||
|
|
||||||
loop64:
|
|
||||||
VPMOVZXDQ (SI), Y0
|
|
||||||
VPMOVZXDQ 16(SI), Y1
|
|
||||||
VPMOVZXDQ 32(SI), Y2
|
|
||||||
VPMOVZXDQ 48(SI), Y3
|
|
||||||
VPADDQ Y0, Y4, Y4
|
|
||||||
VPADDQ Y1, Y5, Y5
|
|
||||||
VPADDQ Y2, Y6, Y6
|
|
||||||
VPADDQ Y3, Y7, Y7
|
|
||||||
ADDQ $64, SI
|
|
||||||
SUBQ $64, CX
|
|
||||||
CMPQ CX, $64
|
|
||||||
JGE loop64
|
|
||||||
|
|
||||||
loop32:
|
|
||||||
CMPQ CX, $32
|
|
||||||
JLT reduce_vec
|
|
||||||
VPMOVZXDQ (SI), Y0
|
|
||||||
VPMOVZXDQ 16(SI), Y1
|
|
||||||
VPADDQ Y0, Y4, Y4
|
|
||||||
VPADDQ Y1, Y5, Y5
|
|
||||||
ADDQ $32, SI
|
|
||||||
SUBQ $32, CX
|
|
||||||
JMP loop32
|
|
||||||
|
|
||||||
reduce_vec:
|
|
||||||
// Combine the four ymm accumulators into Y4.
|
|
||||||
VPADDQ Y5, Y4, Y4
|
|
||||||
VPADDQ Y7, Y6, Y6
|
|
||||||
VPADDQ Y6, Y4, Y4
|
|
||||||
|
|
||||||
// Horizontally reduce Y4's four uint64 lanes to a single scalar.
|
|
||||||
VEXTRACTI128 $1, Y4, X5
|
|
||||||
VPADDQ X5, X4, X4
|
|
||||||
VPSHUFD $0x4e, X4, X5
|
|
||||||
VPADDQ X5, X4, X4
|
|
||||||
VMOVQ X4, R8
|
|
||||||
VZEROUPPER
|
|
||||||
|
|
||||||
ADDQ R8, AX
|
|
||||||
ADCQ $0, AX
|
|
||||||
|
|
||||||
scalar_tail:
|
|
||||||
// Handle remaining 0..63 bytes (or the entire buffer if it was < 32).
|
|
||||||
CMPQ CX, $8
|
|
||||||
JLT tail4
|
|
||||||
|
|
||||||
loop8:
|
|
||||||
ADDQ (SI), AX
|
|
||||||
ADCQ $0, AX
|
|
||||||
ADDQ $8, SI
|
|
||||||
SUBQ $8, CX
|
|
||||||
CMPQ CX, $8
|
|
||||||
JGE loop8
|
|
||||||
|
|
||||||
tail4:
|
|
||||||
CMPQ CX, $4
|
|
||||||
JLT tail2
|
|
||||||
MOVL (SI), R8
|
|
||||||
ADDQ R8, AX
|
|
||||||
ADCQ $0, AX
|
|
||||||
ADDQ $4, SI
|
|
||||||
SUBQ $4, CX
|
|
||||||
|
|
||||||
tail2:
|
|
||||||
CMPQ CX, $2
|
|
||||||
JLT tail1
|
|
||||||
MOVWQZX (SI), R8
|
|
||||||
ADDQ R8, AX
|
|
||||||
ADCQ $0, AX
|
|
||||||
ADDQ $2, SI
|
|
||||||
SUBQ $2, CX
|
|
||||||
|
|
||||||
tail1:
|
|
||||||
TESTQ CX, CX
|
|
||||||
JZ fold
|
|
||||||
MOVBQZX (SI), R8
|
|
||||||
ADDQ R8, AX
|
|
||||||
ADCQ $0, AX
|
|
||||||
|
|
||||||
fold:
|
|
||||||
// Fold the 64-bit accumulator to 16 bits via four rounds, mirroring
|
|
||||||
// gvisor's reduce(). Each pair (split, add) halves the live width;
|
|
||||||
// the truncation steps absorb the single bit that may be left over
|
|
||||||
// after each add so the next round's bound holds.
|
|
||||||
|
|
||||||
// 64 → 33 bits.
|
|
||||||
MOVQ AX, R8
|
|
||||||
SHRQ $32, R8
|
|
||||||
MOVL AX, AX
|
|
||||||
ADDQ R8, AX
|
|
||||||
|
|
||||||
// 33 → 32 bits. AX += (AX>>32); truncate to 32. AX is now ≤ 0xFFFF_FFFF.
|
|
||||||
MOVQ AX, R8
|
|
||||||
SHRQ $32, R8
|
|
||||||
ADDQ R8, AX
|
|
||||||
MOVL AX, AX
|
|
||||||
|
|
||||||
// 32 → 17 bits.
|
|
||||||
MOVQ AX, R8
|
|
||||||
SHRQ $16, R8
|
|
||||||
MOVWQZX AX, AX
|
|
||||||
ADDQ R8, AX
|
|
||||||
|
|
||||||
// 17 → 16 bits. AX += (AX>>16); the trailing MOVW truncates bit 16.
|
|
||||||
MOVQ AX, R8
|
|
||||||
SHRQ $16, R8
|
|
||||||
ADDQ R8, AX
|
|
||||||
|
|
||||||
// AX low 16 bits hold the 16-bit sum in machine (LE) byte order; flip
|
|
||||||
// to big-endian to match the gvisor API contract.
|
|
||||||
XCHGB AH, AL
|
|
||||||
|
|
||||||
MOVW AX, ret+32(FP)
|
|
||||||
RET
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
package checksum
|
|
||||||
|
|
||||||
//go:noescape
|
|
||||||
func checksumNEON(buf []byte, initial uint16) uint16
|
|
||||||
|
|
||||||
// Checksum computes the RFC 1071 ones-complement sum of buf, seeded with
|
|
||||||
// initial. It is a drop-in replacement for gvisor's checksum.Checksum
|
|
||||||
// that dispatches to a hand-written NEON routine. NEON is mandatory in
|
|
||||||
// armv8 so no feature check is needed.
|
|
||||||
func Checksum(buf []byte, initial uint16) uint16 {
|
|
||||||
return checksumNEON(buf, initial)
|
|
||||||
}
|
|
||||||
@@ -1,143 +0,0 @@
|
|||||||
#include "textflag.h"
|
|
||||||
|
|
||||||
// func checksumNEON(buf []byte, initial uint16) uint16
|
|
||||||
//
|
|
||||||
// Mirrors the algorithm in checksum_amd64.s: sum the buffer treating it as
|
|
||||||
// a stream of uint32s in machine (little-endian) byte order, accumulating
|
|
||||||
// into 64-bit lanes that have ample carry headroom; fold and byte-swap once
|
|
||||||
// at the very end to recover the on-wire (big-endian) result.
|
|
||||||
//
|
|
||||||
// Each loop iteration loads 64 bytes via VLD1.P into V0..V3 (4 Q regs).
|
|
||||||
// VUADDW takes the low two uint32 lanes of a Q reg, zero-extends them to
|
|
||||||
// uint64, and adds them into a 2×uint64 accumulator; VUADDW2 does the same
|
|
||||||
// for the high two lanes. Four ymm-equivalent accumulators (V8..V11) get
|
|
||||||
// updated twice per iter to break the dep chain. Tail bytes go through a
|
|
||||||
// scalar ADCS chain seeded with the byte-swapped initial.
|
|
||||||
TEXT ·checksumNEON(SB), NOSPLIT, $0-34
|
|
||||||
MOVD buf_base+0(FP), R0
|
|
||||||
MOVD buf_len+8(FP), R1
|
|
||||||
MOVHU initial+24(FP), R2
|
|
||||||
|
|
||||||
// Pre-byteswap initial into the LE-summing space so it merges directly
|
|
||||||
// with the rest of the accumulator.
|
|
||||||
REV16W R2, R2
|
|
||||||
|
|
||||||
MOVD ZR, R3 // scalar accumulator
|
|
||||||
|
|
||||||
CMP $32, R1
|
|
||||||
BLT scalar_tail
|
|
||||||
|
|
||||||
VEOR V8.B16, V8.B16, V8.B16
|
|
||||||
VEOR V9.B16, V9.B16, V9.B16
|
|
||||||
VEOR V10.B16, V10.B16, V10.B16
|
|
||||||
VEOR V11.B16, V11.B16, V11.B16
|
|
||||||
|
|
||||||
CMP $64, R1
|
|
||||||
BLT loop16_init
|
|
||||||
|
|
||||||
loop64:
|
|
||||||
VLD1.P 64(R0), [V0.B16, V1.B16, V2.B16, V3.B16]
|
|
||||||
VUADDW V0.S2, V8.D2, V8.D2
|
|
||||||
VUADDW2 V0.S4, V9.D2, V9.D2
|
|
||||||
VUADDW V1.S2, V10.D2, V10.D2
|
|
||||||
VUADDW2 V1.S4, V11.D2, V11.D2
|
|
||||||
VUADDW V2.S2, V8.D2, V8.D2
|
|
||||||
VUADDW2 V2.S4, V9.D2, V9.D2
|
|
||||||
VUADDW V3.S2, V10.D2, V10.D2
|
|
||||||
VUADDW2 V3.S4, V11.D2, V11.D2
|
|
||||||
SUB $64, R1, R1
|
|
||||||
CMP $64, R1
|
|
||||||
BGE loop64
|
|
||||||
|
|
||||||
loop16_init:
|
|
||||||
CMP $16, R1
|
|
||||||
BLT reduce_vec
|
|
||||||
|
|
||||||
loop16:
|
|
||||||
VLD1.P 16(R0), [V0.B16]
|
|
||||||
VUADDW V0.S2, V8.D2, V8.D2
|
|
||||||
VUADDW2 V0.S4, V9.D2, V9.D2
|
|
||||||
SUB $16, R1, R1
|
|
||||||
CMP $16, R1
|
|
||||||
BGE loop16
|
|
||||||
|
|
||||||
reduce_vec:
|
|
||||||
// Combine the four accumulators into V8.
|
|
||||||
VADD V9.D2, V8.D2, V8.D2
|
|
||||||
VADD V11.D2, V10.D2, V10.D2
|
|
||||||
VADD V10.D2, V8.D2, V8.D2
|
|
||||||
|
|
||||||
// Horizontal-add the two lanes of V8.D2 into a single uint64.
|
|
||||||
VADDP V8.D2, V8.D2, V8.D2
|
|
||||||
VMOV V8.D[0], R8
|
|
||||||
|
|
||||||
ADDS R8, R3, R3
|
|
||||||
ADC ZR, R3, R3
|
|
||||||
|
|
||||||
scalar_tail:
|
|
||||||
CMP $8, R1
|
|
||||||
BLT tail4
|
|
||||||
|
|
||||||
loop8:
|
|
||||||
MOVD.P 8(R0), R8
|
|
||||||
ADDS R8, R3, R3
|
|
||||||
ADC ZR, R3, R3
|
|
||||||
SUB $8, R1, R1
|
|
||||||
CMP $8, R1
|
|
||||||
BGE loop8
|
|
||||||
|
|
||||||
tail4:
|
|
||||||
CMP $4, R1
|
|
||||||
BLT tail2
|
|
||||||
MOVWU.P 4(R0), R8
|
|
||||||
ADDS R8, R3, R3
|
|
||||||
ADC ZR, R3, R3
|
|
||||||
SUB $4, R1, R1
|
|
||||||
|
|
||||||
tail2:
|
|
||||||
CMP $2, R1
|
|
||||||
BLT tail1
|
|
||||||
MOVHU.P 2(R0), R8
|
|
||||||
ADDS R8, R3, R3
|
|
||||||
ADC ZR, R3, R3
|
|
||||||
SUB $2, R1, R1
|
|
||||||
|
|
||||||
tail1:
|
|
||||||
CBZ R1, fold
|
|
||||||
MOVBU (R0), R8
|
|
||||||
ADDS R8, R3, R3
|
|
||||||
ADC ZR, R3, R3
|
|
||||||
|
|
||||||
fold:
|
|
||||||
// Merge the byte-swapped initial into our LE-form accumulator.
|
|
||||||
ADDS R2, R3, R3
|
|
||||||
ADC ZR, R3, R3
|
|
||||||
|
|
||||||
// 64 → 33 bits.
|
|
||||||
LSR $32, R3, R8
|
|
||||||
AND $0xffffffff, R3, R3
|
|
||||||
ADD R8, R3, R3
|
|
||||||
|
|
||||||
// 33 → 32 (truncate after adding bit 32 back).
|
|
||||||
LSR $32, R3, R8
|
|
||||||
ADD R8, R3, R3
|
|
||||||
AND $0xffffffff, R3, R3
|
|
||||||
|
|
||||||
// 32 → 17.
|
|
||||||
LSR $16, R3, R8
|
|
||||||
AND $0xffff, R3, R3
|
|
||||||
ADD R8, R3, R3
|
|
||||||
|
|
||||||
// 17 → 16 (truncation absorbs bit 16 below).
|
|
||||||
LSR $16, R3, R8
|
|
||||||
ADD R8, R3, R3
|
|
||||||
|
|
||||||
// AX low 16 bits hold the 16-bit sum in machine (LE) byte order; flip
|
|
||||||
// to big-endian to match the gvisor API contract. REV16W swaps bytes
|
|
||||||
// within each 16-bit halfword of the low 32 bits, so it acts as a
|
|
||||||
// 16-bit byte-swap on the live low 16.
|
|
||||||
REV16W R3, R3
|
|
||||||
AND $0xffff, R3, R3
|
|
||||||
|
|
||||||
MOVH R3, ret+32(FP)
|
|
||||||
RET
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
//go:build !amd64 && !arm64
|
|
||||||
|
|
||||||
package checksum
|
|
||||||
|
|
||||||
import gvisorchecksum "gvisor.dev/gvisor/pkg/tcpip/checksum"
|
|
||||||
|
|
||||||
// Checksum delegates to gvisor on architectures without a hand-written body.
|
|
||||||
func Checksum(buf []byte, initial uint16) uint16 {
|
|
||||||
return gvisorchecksum.Checksum(buf, initial)
|
|
||||||
}
|
|
||||||
@@ -1,190 +0,0 @@
|
|||||||
package checksum
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"math/rand/v2"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
gvisorchecksum "gvisor.dev/gvisor/pkg/tcpip/checksum"
|
|
||||||
)
|
|
||||||
|
|
||||||
// TestChecksumMatchesGvisor walks lengths from 0 to 4096, with several initial
|
|
||||||
// seeds and a handful of starting alignments, asserting that our local
|
|
||||||
// Checksum matches gvisor's reference bit-for-bit.
|
|
||||||
func TestChecksumMatchesGvisor(t *testing.T) {
|
|
||||||
rng := rand.New(rand.NewPCG(1, 2))
|
|
||||||
const padFront = 16
|
|
||||||
|
|
||||||
// Random pool large enough for the longest case + alignment slop.
|
|
||||||
pool := make([]byte, 4096+padFront)
|
|
||||||
for i := range pool {
|
|
||||||
pool[i] = byte(rng.Uint32())
|
|
||||||
}
|
|
||||||
|
|
||||||
seeds := []uint16{0, 0x0001, 0xabcd, 0xffff, 0x1234, 0xfedc}
|
|
||||||
offsets := []int{0, 1, 2, 3, 4, 5, 7, 8, 15, 16}
|
|
||||||
|
|
||||||
for length := 0; length <= 4096; length++ {
|
|
||||||
for _, seed := range seeds {
|
|
||||||
for _, off := range offsets {
|
|
||||||
if off+length > len(pool) {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
buf := pool[off : off+length]
|
|
||||||
want := gvisorchecksum.Checksum(buf, seed)
|
|
||||||
got := Checksum(buf, seed)
|
|
||||||
if got != want {
|
|
||||||
t.Fatalf("len=%d off=%d seed=%#x: got %#04x want %#04x",
|
|
||||||
length, off, seed, got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestChecksumPatternedBuffers exercises specific byte patterns that have
|
|
||||||
// historically tripped up checksum implementations: all-zero, all-0xff,
|
|
||||||
// alternating, and ascending sequences.
|
|
||||||
func TestChecksumPatternedBuffers(t *testing.T) {
|
|
||||||
for length := 0; length <= 256; length++ {
|
|
||||||
patterns := map[string][]byte{
|
|
||||||
"zeros": make([]byte, length),
|
|
||||||
"ones": bytes(length, 0xff),
|
|
||||||
"alternating": pattern(length, []byte{0xa5, 0x5a}),
|
|
||||||
"ascending": ascending(length),
|
|
||||||
}
|
|
||||||
for name, buf := range patterns {
|
|
||||||
for _, seed := range []uint16{0, 0xffff, 0x8000} {
|
|
||||||
want := gvisorchecksum.Checksum(buf, seed)
|
|
||||||
got := Checksum(buf, seed)
|
|
||||||
if got != want {
|
|
||||||
t.Fatalf("%s len=%d seed=%#x: got %#04x want %#04x",
|
|
||||||
name, length, seed, got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func bytes(n int, v byte) []byte {
|
|
||||||
b := make([]byte, n)
|
|
||||||
for i := range b {
|
|
||||||
b[i] = v
|
|
||||||
}
|
|
||||||
return b
|
|
||||||
}
|
|
||||||
|
|
||||||
func pattern(n int, p []byte) []byte {
|
|
||||||
b := make([]byte, n)
|
|
||||||
for i := range b {
|
|
||||||
b[i] = p[i%len(p)]
|
|
||||||
}
|
|
||||||
return b
|
|
||||||
}
|
|
||||||
|
|
||||||
func ascending(n int) []byte {
|
|
||||||
b := make([]byte, n)
|
|
||||||
for i := range b {
|
|
||||||
b[i] = byte(i)
|
|
||||||
}
|
|
||||||
return b
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestChecksumTailPaths targets every combination of (SIMD body iterations,
|
|
||||||
// trailing tail bytes) the asm handlers walk through. The tail handlers
|
|
||||||
// peel off 8 → 4 → 2 → 1 byte chunks in turn; this test exercises each by
|
|
||||||
// constructing lengths of the form 64*k + tail for tail ∈ [0, 63] and a
|
|
||||||
// representative spread of k values, including k=0 (no main loop, all tail)
|
|
||||||
// and k=1 (one main loop iter, then tail). It's explicit coverage for
|
|
||||||
// payload sizes that are odd, not divisible by 4, by 8, or by 32.
|
|
||||||
func TestChecksumTailPaths(t *testing.T) {
|
|
||||||
rng := rand.New(rand.NewPCG(42, 17))
|
|
||||||
const padFront = 16
|
|
||||||
const maxK = 8
|
|
||||||
|
|
||||||
pool := make([]byte, 64*maxK+padFront+64)
|
|
||||||
for i := range pool {
|
|
||||||
pool[i] = byte(rng.Uint32())
|
|
||||||
}
|
|
||||||
|
|
||||||
seeds := []uint16{0, 0xffff, 0xabcd}
|
|
||||||
offsets := []int{0, 1, 3, 7, 15} // mix of aligned and odd starts
|
|
||||||
|
|
||||||
for k := 0; k <= maxK; k++ {
|
|
||||||
for tail := 0; tail < 64; tail++ {
|
|
||||||
length := 64*k + tail
|
|
||||||
for _, seed := range seeds {
|
|
||||||
for _, off := range offsets {
|
|
||||||
if off+length > len(pool) {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
buf := pool[off : off+length]
|
|
||||||
want := gvisorchecksum.Checksum(buf, seed)
|
|
||||||
got := Checksum(buf, seed)
|
|
||||||
if got != want {
|
|
||||||
t.Fatalf("k=%d tail=%d (len=%d) off=%d seed=%#x: got %#04x want %#04x",
|
|
||||||
k, tail, length, off, seed, got, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkChecksumTailSizes covers payload sizes that aren't clean multiples
|
|
||||||
// of the SIMD body's 32-byte (amd64) or 16-byte (arm64) chunks, so the tail
|
|
||||||
// handler is meaningfully on the hot path. Sizes are picked to either exercise
|
|
||||||
// every tail branch (tiny lengths) or sit slightly off realistic packet
|
|
||||||
// boundaries (e.g. 1499 = MTU − 1).
|
|
||||||
func BenchmarkChecksumTailSizes(b *testing.B) {
|
|
||||||
sizes := []int{
|
|
||||||
1, 3, 7, 15, 31, // sub-SIMD; entire work is scalar tail
|
|
||||||
33, 35, 47, 63, // one loop32 + assorted tails
|
|
||||||
65, 95, 127, // one loop64 + assorted tails
|
|
||||||
1447, 1471, 1499, 1501, // around MTU
|
|
||||||
8191, 8193, // around USO
|
|
||||||
65531, 65533, // near the kernel max
|
|
||||||
}
|
|
||||||
for _, size := range sizes {
|
|
||||||
buf := make([]byte, size)
|
|
||||||
for i := range buf {
|
|
||||||
buf[i] = byte(i)
|
|
||||||
}
|
|
||||||
b.Run(fmt.Sprintf("size=%d/local", size), func(b *testing.B) {
|
|
||||||
b.SetBytes(int64(size))
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
_ = Checksum(buf, 0)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
b.Run(fmt.Sprintf("size=%d/gvisor", size), func(b *testing.B) {
|
|
||||||
b.SetBytes(int64(size))
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
_ = gvisorchecksum.Checksum(buf, 0)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkChecksum compares the local Checksum to gvisor's at sizes that
|
|
||||||
// match real traffic: a TCP/IP header (60), a typical MSS (1448), a typical
|
|
||||||
// USO size (8192), and the kernel's max GSO superpacket (65535).
|
|
||||||
func BenchmarkChecksum(b *testing.B) {
|
|
||||||
for _, size := range []int{60, 1448, 8192, 65535} {
|
|
||||||
buf := make([]byte, size)
|
|
||||||
for i := range buf {
|
|
||||||
buf[i] = byte(i)
|
|
||||||
}
|
|
||||||
b.Run(fmt.Sprintf("size=%d/local", size), func(b *testing.B) {
|
|
||||||
b.SetBytes(int64(size))
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
_ = Checksum(buf, 0)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
b.Run(fmt.Sprintf("size=%d/gvisor", size), func(b *testing.B) {
|
|
||||||
b.SetBytes(int64(size))
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
_ = gvisorchecksum.Checksum(buf, 0)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+11
-8
@@ -4,21 +4,24 @@ import (
|
|||||||
"io"
|
"io"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
)
|
)
|
||||||
|
|
||||||
// defaultBatchBufSize is the per-Queue scratch size for Read on backends
|
|
||||||
// that don't do TSO segmentation. 65535 covers any single IP packet.
|
|
||||||
const defaultBatchBufSize = 65535
|
|
||||||
|
|
||||||
type Device interface {
|
type Device interface {
|
||||||
io.Closer
|
io.ReadWriteCloser
|
||||||
Activate() error
|
Activate() error
|
||||||
Networks() []netip.Prefix
|
Networks() []netip.Prefix
|
||||||
Name() string
|
Name() string
|
||||||
RoutesFor(netip.Addr) routing.Gateways
|
RoutesFor(netip.Addr) routing.Gateways
|
||||||
SupportsMultiqueue() bool
|
SupportsMultiqueue() bool
|
||||||
NewMultiQueueReader() error
|
NewMultiQueueReader() (io.ReadWriteCloser, error)
|
||||||
Readers() []tio.Queue
|
// SupportsPerPeerMTU reports whether SetPeerMTU is implemented for real on
|
||||||
|
// this platform. PMTUD requires this; the manager will refuse to enable when
|
||||||
|
// false even if the operator set tun.max_mtu, because a discovered MTU we
|
||||||
|
// can't actually install does the operator no good.
|
||||||
|
SupportsPerPeerMTU() bool
|
||||||
|
// SetPeerMTU installs a per-peer MTU on the routing table so the kernel will
|
||||||
|
// surface PTB / EMSGSIZE for inside packets to that peer that would exceed mtu.
|
||||||
|
// Pass mtu=0 to remove the override and let the device default apply.
|
||||||
|
SetPeerMTU(addr netip.Addr, mtu int) error
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,358 +0,0 @@
|
|||||||
//go:build !e2e_testing
|
|
||||||
// +build !e2e_testing
|
|
||||||
|
|
||||||
package overlay
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
"log/slog"
|
|
||||||
"runtime"
|
|
||||||
"strings"
|
|
||||||
"syscall"
|
|
||||||
"time"
|
|
||||||
"unsafe"
|
|
||||||
|
|
||||||
"golang.org/x/sys/windows"
|
|
||||||
)
|
|
||||||
|
|
||||||
// networkCategory mirrors NLM_NETWORK_CATEGORY from netlistmgr.h.
|
|
||||||
type networkCategory int32
|
|
||||||
|
|
||||||
const (
|
|
||||||
networkCategoryPublic networkCategory = 0
|
|
||||||
networkCategoryPrivate networkCategory = 1
|
|
||||||
networkCategoryDomainAuthenticated networkCategory = 2
|
|
||||||
)
|
|
||||||
|
|
||||||
func (c networkCategory) String() string {
|
|
||||||
switch c {
|
|
||||||
case networkCategoryPublic:
|
|
||||||
return "public"
|
|
||||||
case networkCategoryPrivate:
|
|
||||||
return "private"
|
|
||||||
case networkCategoryDomainAuthenticated:
|
|
||||||
return "domain"
|
|
||||||
}
|
|
||||||
return fmt.Sprintf("unknown(%d)", c)
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseNetworkCategory accepts the user-supplied tun.network_category. A
|
|
||||||
// second return of false means "leave the category alone".
|
|
||||||
func parseNetworkCategory(s string) (networkCategory, bool, error) {
|
|
||||||
switch strings.ToLower(strings.TrimSpace(s)) {
|
|
||||||
case "", "unset":
|
|
||||||
return 0, false, nil
|
|
||||||
case "public":
|
|
||||||
return networkCategoryPublic, true, nil
|
|
||||||
case "private":
|
|
||||||
return networkCategoryPrivate, true, nil
|
|
||||||
case "domain", "domainauthenticated":
|
|
||||||
return networkCategoryDomainAuthenticated, true, nil
|
|
||||||
}
|
|
||||||
return 0, false, fmt.Errorf("unknown tun.network_category %q (expected public, private, domain, or unset)", s)
|
|
||||||
}
|
|
||||||
|
|
||||||
// CLSID_NetworkListManager {DCB00C01-570F-4A9B-8D69-199FDBA5723B}
|
|
||||||
var clsidNetworkListManager = windows.GUID{
|
|
||||||
Data1: 0xDCB00C01, Data2: 0x570F, Data3: 0x4A9B,
|
|
||||||
Data4: [8]byte{0x8D, 0x69, 0x19, 0x9F, 0xDB, 0xA5, 0x72, 0x3B},
|
|
||||||
}
|
|
||||||
|
|
||||||
// IID_INetworkListManager {DCB00000-570F-4A9B-8D69-199FDBA5723B}
|
|
||||||
var iidINetworkListManager = windows.GUID{
|
|
||||||
Data1: 0xDCB00000, Data2: 0x570F, Data3: 0x4A9B,
|
|
||||||
Data4: [8]byte{0x8D, 0x69, 0x19, 0x9F, 0xDB, 0xA5, 0x72, 0x3B},
|
|
||||||
}
|
|
||||||
|
|
||||||
// x/sys/windows doesn't expose CoCreateInstance, so we bind it ourselves.
|
|
||||||
var procCoCreateInstance = windows.NewLazySystemDLL("ole32.dll").NewProc("CoCreateInstance")
|
|
||||||
|
|
||||||
const clsCtxAll = windows.CLSCTX_INPROC_SERVER | windows.CLSCTX_INPROC_HANDLER |
|
|
||||||
windows.CLSCTX_LOCAL_SERVER | windows.CLSCTX_REMOTE_SERVER
|
|
||||||
|
|
||||||
const (
|
|
||||||
hrSFALSE = 0x00000001
|
|
||||||
hrRPCEChangedMode = 0x80010106
|
|
||||||
)
|
|
||||||
|
|
||||||
type hresult uint32
|
|
||||||
|
|
||||||
func (h hresult) failed() bool { return int32(h) < 0 }
|
|
||||||
func (h hresult) String() string {
|
|
||||||
return fmt.Sprintf("HRESULT 0x%08x", uint32(h))
|
|
||||||
}
|
|
||||||
|
|
||||||
var errAdapterNotFound = errors.New("adapter not present in network connections enumeration")
|
|
||||||
|
|
||||||
// Vtable layouts. Slot order must match the declaration order in netlistmgr.h.
|
|
||||||
// All NLM interfaces here derive from IDispatch, which derives from IUnknown.
|
|
||||||
|
|
||||||
type iUnknownVtbl struct {
|
|
||||||
QueryInterface uintptr
|
|
||||||
AddRef uintptr
|
|
||||||
Release uintptr
|
|
||||||
}
|
|
||||||
|
|
||||||
type iDispatchVtbl struct {
|
|
||||||
iUnknownVtbl
|
|
||||||
GetTypeInfoCount uintptr
|
|
||||||
GetTypeInfo uintptr
|
|
||||||
GetIDsOfNames uintptr
|
|
||||||
Invoke uintptr
|
|
||||||
}
|
|
||||||
|
|
||||||
type iNetworkListManagerVtbl struct {
|
|
||||||
iDispatchVtbl
|
|
||||||
GetNetworks uintptr
|
|
||||||
GetNetwork uintptr
|
|
||||||
GetNetworkConnections uintptr
|
|
||||||
GetNetworkConnection uintptr
|
|
||||||
IsConnectedToInternet uintptr
|
|
||||||
IsConnected uintptr
|
|
||||||
GetConnectivity uintptr
|
|
||||||
}
|
|
||||||
|
|
||||||
type iNetworkListManager struct{ Vtbl *iNetworkListManagerVtbl }
|
|
||||||
|
|
||||||
func (n *iNetworkListManager) Release() {
|
|
||||||
syscall.SyscallN(n.Vtbl.Release, uintptr(unsafe.Pointer(n)))
|
|
||||||
}
|
|
||||||
|
|
||||||
func (n *iNetworkListManager) GetNetworkConnections() (*iEnumNetworkConnections, error) {
|
|
||||||
var enum *iEnumNetworkConnections
|
|
||||||
r1, _, _ := syscall.SyscallN(n.Vtbl.GetNetworkConnections,
|
|
||||||
uintptr(unsafe.Pointer(n)), uintptr(unsafe.Pointer(&enum)),
|
|
||||||
)
|
|
||||||
if hr := hresult(r1); hr.failed() {
|
|
||||||
return nil, fmt.Errorf("INetworkListManager.GetNetworkConnections: %s", hr)
|
|
||||||
}
|
|
||||||
return enum, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
type iEnumNetworkConnectionsVtbl struct {
|
|
||||||
iDispatchVtbl
|
|
||||||
NewEnum uintptr
|
|
||||||
Next uintptr
|
|
||||||
Skip uintptr
|
|
||||||
Reset uintptr
|
|
||||||
Clone uintptr
|
|
||||||
}
|
|
||||||
|
|
||||||
type iEnumNetworkConnections struct{ Vtbl *iEnumNetworkConnectionsVtbl }
|
|
||||||
|
|
||||||
func (e *iEnumNetworkConnections) Release() {
|
|
||||||
syscall.SyscallN(e.Vtbl.Release, uintptr(unsafe.Pointer(e)))
|
|
||||||
}
|
|
||||||
|
|
||||||
// Next returns the next connection, or (nil, nil) at the end of the enumeration.
|
|
||||||
func (e *iEnumNetworkConnections) Next() (*iNetworkConnection, error) {
|
|
||||||
var conn *iNetworkConnection
|
|
||||||
var fetched uint32
|
|
||||||
r1, _, _ := syscall.SyscallN(e.Vtbl.Next,
|
|
||||||
uintptr(unsafe.Pointer(e)), 1,
|
|
||||||
uintptr(unsafe.Pointer(&conn)), uintptr(unsafe.Pointer(&fetched)),
|
|
||||||
)
|
|
||||||
if hr := hresult(r1); hr.failed() {
|
|
||||||
return nil, fmt.Errorf("IEnumNetworkConnections.Next: %s", hr)
|
|
||||||
}
|
|
||||||
if fetched == 0 {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
return conn, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
type iNetworkConnectionVtbl struct {
|
|
||||||
iDispatchVtbl
|
|
||||||
GetNetwork uintptr
|
|
||||||
IsConnectedToInternet uintptr
|
|
||||||
IsConnected uintptr
|
|
||||||
GetConnectivity uintptr
|
|
||||||
GetConnectionId uintptr
|
|
||||||
GetAdapterId uintptr
|
|
||||||
GetDomainType uintptr
|
|
||||||
}
|
|
||||||
|
|
||||||
type iNetworkConnection struct{ Vtbl *iNetworkConnectionVtbl }
|
|
||||||
|
|
||||||
func (c *iNetworkConnection) Release() {
|
|
||||||
syscall.SyscallN(c.Vtbl.Release, uintptr(unsafe.Pointer(c)))
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *iNetworkConnection) GetAdapterId() (windows.GUID, error) {
|
|
||||||
var g windows.GUID
|
|
||||||
r1, _, _ := syscall.SyscallN(c.Vtbl.GetAdapterId,
|
|
||||||
uintptr(unsafe.Pointer(c)), uintptr(unsafe.Pointer(&g)),
|
|
||||||
)
|
|
||||||
if hr := hresult(r1); hr.failed() {
|
|
||||||
return windows.GUID{}, fmt.Errorf("INetworkConnection.GetAdapterId: %s", hr)
|
|
||||||
}
|
|
||||||
return g, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *iNetworkConnection) GetNetwork() (*iNetwork, error) {
|
|
||||||
var net *iNetwork
|
|
||||||
r1, _, _ := syscall.SyscallN(c.Vtbl.GetNetwork,
|
|
||||||
uintptr(unsafe.Pointer(c)), uintptr(unsafe.Pointer(&net)),
|
|
||||||
)
|
|
||||||
if hr := hresult(r1); hr.failed() {
|
|
||||||
return nil, fmt.Errorf("INetworkConnection.GetNetwork: %s", hr)
|
|
||||||
}
|
|
||||||
return net, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
type iNetworkVtbl struct {
|
|
||||||
iDispatchVtbl
|
|
||||||
GetName uintptr
|
|
||||||
SetName uintptr
|
|
||||||
GetDescription uintptr
|
|
||||||
SetDescription uintptr
|
|
||||||
GetNetworkId uintptr
|
|
||||||
GetDomainType uintptr
|
|
||||||
GetNetworkConnections uintptr
|
|
||||||
GetTimeCreatedAndConnected uintptr
|
|
||||||
IsConnectedToInternet uintptr
|
|
||||||
IsConnected uintptr
|
|
||||||
GetConnectivity uintptr
|
|
||||||
GetCategory uintptr
|
|
||||||
SetCategory uintptr
|
|
||||||
}
|
|
||||||
|
|
||||||
type iNetwork struct{ Vtbl *iNetworkVtbl }
|
|
||||||
|
|
||||||
func (n *iNetwork) Release() {
|
|
||||||
syscall.SyscallN(n.Vtbl.Release, uintptr(unsafe.Pointer(n)))
|
|
||||||
}
|
|
||||||
|
|
||||||
func (n *iNetwork) GetCategory() (networkCategory, error) {
|
|
||||||
var c networkCategory
|
|
||||||
r1, _, _ := syscall.SyscallN(n.Vtbl.GetCategory,
|
|
||||||
uintptr(unsafe.Pointer(n)), uintptr(unsafe.Pointer(&c)),
|
|
||||||
)
|
|
||||||
if hr := hresult(r1); hr.failed() {
|
|
||||||
return 0, fmt.Errorf("INetwork.GetCategory: %s", hr)
|
|
||||||
}
|
|
||||||
return c, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (n *iNetwork) SetCategory(c networkCategory) error {
|
|
||||||
r1, _, _ := syscall.SyscallN(n.Vtbl.SetCategory,
|
|
||||||
uintptr(unsafe.Pointer(n)), uintptr(int32(c)),
|
|
||||||
)
|
|
||||||
if hr := hresult(r1); hr.failed() {
|
|
||||||
return fmt.Errorf("INetwork.SetCategory: %s", hr)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// coInit initializes COM for the current OS thread. The returned function must
|
|
||||||
// be deferred to balance a successful init. RPC_E_CHANGED_MODE means COM is
|
|
||||||
// already initialized in a different mode on this thread, which is still fine
|
|
||||||
// for our calls but we must not Uninitialize in that case.
|
|
||||||
func coInit() (func(), error) {
|
|
||||||
err := windows.CoInitializeEx(0, windows.COINIT_MULTITHREADED)
|
|
||||||
if err == nil {
|
|
||||||
return windows.CoUninitialize, nil
|
|
||||||
}
|
|
||||||
if e, ok := err.(syscall.Errno); ok {
|
|
||||||
switch uint32(e) {
|
|
||||||
case hrSFALSE:
|
|
||||||
return windows.CoUninitialize, nil
|
|
||||||
case hrRPCEChangedMode:
|
|
||||||
return func() {}, nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return nil, fmt.Errorf("CoInitializeEx: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
func createNetworkListManager() (*iNetworkListManager, error) {
|
|
||||||
var nlm *iNetworkListManager
|
|
||||||
r1, _, _ := procCoCreateInstance.Call(
|
|
||||||
uintptr(unsafe.Pointer(&clsidNetworkListManager)),
|
|
||||||
0,
|
|
||||||
uintptr(clsCtxAll),
|
|
||||||
uintptr(unsafe.Pointer(&iidINetworkListManager)),
|
|
||||||
uintptr(unsafe.Pointer(&nlm)),
|
|
||||||
)
|
|
||||||
if hr := hresult(r1); hr.failed() {
|
|
||||||
return nil, fmt.Errorf("CoCreateInstance(NetworkListManager): %s", hr)
|
|
||||||
}
|
|
||||||
return nlm, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// setNetworkCategory locates the network connection bound to adapterGUID and
|
|
||||||
// sets the category of its parent network. Returns errAdapterNotFound if the
|
|
||||||
// adapter is not yet visible in the NLM enumeration.
|
|
||||||
func setNetworkCategory(adapterGUID windows.GUID, cat networkCategory) error {
|
|
||||||
deinit, err := coInit()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer deinit()
|
|
||||||
|
|
||||||
nlm, err := createNetworkListManager()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer nlm.Release()
|
|
||||||
|
|
||||||
enum, err := nlm.GetNetworkConnections()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer enum.Release()
|
|
||||||
|
|
||||||
for {
|
|
||||||
conn, err := enum.Next()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if conn == nil {
|
|
||||||
return errAdapterNotFound
|
|
||||||
}
|
|
||||||
|
|
||||||
guid, err := conn.GetAdapterId()
|
|
||||||
if err != nil || guid != adapterGUID {
|
|
||||||
conn.Release()
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
net, err := conn.GetNetwork()
|
|
||||||
conn.Release()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
err = net.SetCategory(cat)
|
|
||||||
net.Release()
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// applyNetworkCategory polls until the wintun adapter shows up in the NLM
|
|
||||||
// enumeration, then sets the category. Intended to run in its own goroutine.
|
|
||||||
func applyNetworkCategory(l *slog.Logger, adapterGUID windows.GUID, cat networkCategory) {
|
|
||||||
// COM Init/Uninit must be paired on the same OS thread.
|
|
||||||
runtime.LockOSThread()
|
|
||||||
defer runtime.UnlockOSThread()
|
|
||||||
|
|
||||||
const (
|
|
||||||
attempts = 30
|
|
||||||
interval = 500 * time.Millisecond
|
|
||||||
)
|
|
||||||
for i := 0; i < attempts; i++ {
|
|
||||||
err := setNetworkCategory(adapterGUID, cat)
|
|
||||||
if err == nil {
|
|
||||||
l.Info("Set Windows network category", "category", cat.String())
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if !errors.Is(err, errAdapterNotFound) {
|
|
||||||
l.Warn("Failed to set Windows network category", "error", err, "category", cat.String())
|
|
||||||
return
|
|
||||||
}
|
|
||||||
time.Sleep(interval)
|
|
||||||
}
|
|
||||||
l.Warn("Gave up waiting for adapter to appear in NLM enumeration; network category not set",
|
|
||||||
"category", cat.String(),
|
|
||||||
"waited", time.Duration(attempts)*interval,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
@@ -1,109 +0,0 @@
|
|||||||
//go:build !e2e_testing
|
|
||||||
// +build !e2e_testing
|
|
||||||
|
|
||||||
package overlay
|
|
||||||
|
|
||||||
import (
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
func Test_parseNetworkCategory(t *testing.T) {
|
|
||||||
cases := []struct {
|
|
||||||
in string
|
|
||||||
wantCat networkCategory
|
|
||||||
wantApply bool
|
|
||||||
wantErr bool
|
|
||||||
}{
|
|
||||||
{"", 0, false, false},
|
|
||||||
{"unset", 0, false, false},
|
|
||||||
{" UNSET ", 0, false, false},
|
|
||||||
{"private", networkCategoryPrivate, true, false},
|
|
||||||
{"Private", networkCategoryPrivate, true, false},
|
|
||||||
{" PRIVATE ", networkCategoryPrivate, true, false},
|
|
||||||
{"public", networkCategoryPublic, true, false},
|
|
||||||
{"PUBLIC", networkCategoryPublic, true, false},
|
|
||||||
{"domain", networkCategoryDomainAuthenticated, true, false},
|
|
||||||
{"DomainAuthenticated", networkCategoryDomainAuthenticated, true, false},
|
|
||||||
{"garbage", 0, false, true},
|
|
||||||
{"privates", 0, false, true},
|
|
||||||
}
|
|
||||||
for _, tc := range cases {
|
|
||||||
cat, apply, err := parseNetworkCategory(tc.in)
|
|
||||||
if (err != nil) != tc.wantErr {
|
|
||||||
t.Errorf("parseNetworkCategory(%q) err=%v, wantErr=%v", tc.in, err, tc.wantErr)
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if cat != tc.wantCat || apply != tc.wantApply {
|
|
||||||
t.Errorf("parseNetworkCategory(%q) = (%v, %v), want (%v, %v)", tc.in, cat, apply, tc.wantCat, tc.wantApply)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Test_NLM_round_trip exercises every COM call path used by setNetworkCategory
|
|
||||||
// without mutating the host's network state. It validates the CLSID/IID
|
|
||||||
// constants and every vtable index by enumerating connections, fetching the
|
|
||||||
// adapter id and parent network, reading the current category, and writing it
|
|
||||||
// back unchanged.
|
|
||||||
//
|
|
||||||
// Requires Windows but does not require admin or the wintun driver. Skips if
|
|
||||||
// no network connections are available (unlikely outside of an isolated
|
|
||||||
// container).
|
|
||||||
func Test_NLM_round_trip(t *testing.T) {
|
|
||||||
deinit, err := coInit()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("coInit: %v", err)
|
|
||||||
}
|
|
||||||
defer deinit()
|
|
||||||
|
|
||||||
nlm, err := createNetworkListManager()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("createNetworkListManager: %v", err)
|
|
||||||
}
|
|
||||||
defer nlm.Release()
|
|
||||||
|
|
||||||
enum, err := nlm.GetNetworkConnections()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("GetNetworkConnections: %v", err)
|
|
||||||
}
|
|
||||||
defer enum.Release()
|
|
||||||
|
|
||||||
saw := 0
|
|
||||||
for {
|
|
||||||
conn, err := enum.Next()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("EnumNetworkConnections.Next: %v", err)
|
|
||||||
}
|
|
||||||
if conn == nil {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
saw++
|
|
||||||
|
|
||||||
if _, err := conn.GetAdapterId(); err != nil {
|
|
||||||
conn.Release()
|
|
||||||
t.Fatalf("INetworkConnection.GetAdapterId: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
net, err := conn.GetNetwork()
|
|
||||||
conn.Release()
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("INetworkConnection.GetNetwork: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
cat, err := net.GetCategory()
|
|
||||||
if err != nil {
|
|
||||||
net.Release()
|
|
||||||
t.Fatalf("INetwork.GetCategory: %v", err)
|
|
||||||
}
|
|
||||||
// Set to the current value so the host's NLM state is unchanged but
|
|
||||||
// SetCategory's vtable slot is still validated end-to-end.
|
|
||||||
if err := net.SetCategory(cat); err != nil {
|
|
||||||
net.Release()
|
|
||||||
t.Fatalf("INetwork.SetCategory(%v): %v", cat, err)
|
|
||||||
}
|
|
||||||
net.Release()
|
|
||||||
}
|
|
||||||
|
|
||||||
if saw == 0 {
|
|
||||||
t.Skip("no NLM network connections available; skipping round-trip")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+12
-13
@@ -4,11 +4,10 @@ package overlaytest
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"errors"
|
"errors"
|
||||||
|
"io"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// NoopTun is an overlay.Device that silently discards every read and write.
|
// NoopTun is an overlay.Device that silently discards every read and write.
|
||||||
@@ -16,10 +15,6 @@ import (
|
|||||||
// exercise the datapath.
|
// exercise the datapath.
|
||||||
type NoopTun struct{}
|
type NoopTun struct{}
|
||||||
|
|
||||||
func (NoopTun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (NoopTun) RoutesFor(addr netip.Addr) routing.Gateways {
|
func (NoopTun) RoutesFor(addr netip.Addr) routing.Gateways {
|
||||||
return routing.Gateways{}
|
return routing.Gateways{}
|
||||||
}
|
}
|
||||||
@@ -36,7 +31,7 @@ func (NoopTun) Name() string {
|
|||||||
return "noop"
|
return "noop"
|
||||||
}
|
}
|
||||||
|
|
||||||
func (NoopTun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
func (NoopTun) Read([]byte) (int, error) {
|
||||||
return 0, nil
|
return 0, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -44,16 +39,20 @@ func (NoopTun) Write([]byte) (int, error) {
|
|||||||
return 0, nil
|
return 0, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (NoopTun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (NoopTun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (NoopTun) SupportsMultiqueue() bool {
|
func (NoopTun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (NoopTun) NewMultiQueueReader() error {
|
func (NoopTun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return errors.New("unsupported")
|
return nil, errors.New("unsupported")
|
||||||
}
|
|
||||||
|
|
||||||
func (NoopTun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{NoopTun{}}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (NoopTun) Close() error {
|
func (NoopTun) Close() error {
|
||||||
|
|||||||
@@ -1,90 +0,0 @@
|
|||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
)
|
|
||||||
|
|
||||||
type offloadQueueSet struct {
|
|
||||||
pq []*Offload
|
|
||||||
// pqi is exactly the same as pq, but stored as the interface type
|
|
||||||
pqi []Queue
|
|
||||||
shutdownFd int
|
|
||||||
// usoEnabled is true when newTun successfully negotiated TUN_F_USO4|6
|
|
||||||
// with the kernel. Queues created by Add inherit this and surface it
|
|
||||||
// via Offload.USOSupported so coalescers can gate USO emission.
|
|
||||||
usoEnabled bool
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewOffloadQueueSet creates a QueueSet that uses virtio_net_hdr to do
|
|
||||||
// TSO segmentation in userspace. usoEnabled tells downstream queues whether
|
|
||||||
// the kernel agreed to deliver/accept GSO_UDP_L4 superpackets — coalescers
|
|
||||||
// should fall back to per-packet writes when this is false.
|
|
||||||
func NewOffloadQueueSet(usoEnabled bool) (QueueSet, error) {
|
|
||||||
shutdownFd, err := unix.Eventfd(0, unix.EFD_NONBLOCK|unix.EFD_CLOEXEC)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to create eventfd: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
out := &offloadQueueSet{
|
|
||||||
pq: []*Offload{},
|
|
||||||
pqi: []Queue{},
|
|
||||||
shutdownFd: shutdownFd,
|
|
||||||
usoEnabled: usoEnabled,
|
|
||||||
}
|
|
||||||
|
|
||||||
return out, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *offloadQueueSet) Queues() []Queue {
|
|
||||||
return c.pqi
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *offloadQueueSet) Add(fd int) error {
|
|
||||||
x, err := newOffload(fd, c.shutdownFd, c.usoEnabled)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
c.pq = append(c.pq, x)
|
|
||||||
c.pqi = append(c.pqi, x)
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *offloadQueueSet) wakeForShutdown() error {
|
|
||||||
var buf [8]byte
|
|
||||||
binary.NativeEndian.PutUint64(buf[:], 1)
|
|
||||||
_, err := unix.Write(c.shutdownFd, buf[:])
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *offloadQueueSet) Close() error {
|
|
||||||
if c.shutdownFd < 0 {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
errs := []error{}
|
|
||||||
|
|
||||||
// Signal all readers blocked in poll to wake up and exit
|
|
||||||
if err := c.wakeForShutdown(); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, x := range c.pq {
|
|
||||||
if err := x.Close(); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// All Offloads reference shutdownFd in their pollfd arrays, so close it
|
|
||||||
// only after every Offload.Close has returned.
|
|
||||||
if err := unix.Close(c.shutdownFd); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
c.shutdownFd = -1
|
|
||||||
|
|
||||||
return errors.Join(errs...)
|
|
||||||
}
|
|
||||||
@@ -1,80 +0,0 @@
|
|||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
)
|
|
||||||
|
|
||||||
type pollQueueSet struct {
|
|
||||||
pq []*Poll
|
|
||||||
// pqi is exactly the same as pq, but stored as the interface type
|
|
||||||
pqi []Queue
|
|
||||||
shutdownFd int
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewPollQueueSet() (QueueSet, error) {
|
|
||||||
shutdownFd, err := unix.Eventfd(0, unix.EFD_NONBLOCK|unix.EFD_CLOEXEC)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to create eventfd: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
out := &pollQueueSet{
|
|
||||||
pq: []*Poll{},
|
|
||||||
pqi: []Queue{},
|
|
||||||
shutdownFd: shutdownFd,
|
|
||||||
}
|
|
||||||
|
|
||||||
return out, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *pollQueueSet) Queues() []Queue {
|
|
||||||
return c.pqi
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *pollQueueSet) Add(fd int) error {
|
|
||||||
x, err := newPoll(fd, c.shutdownFd)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
c.pq = append(c.pq, x)
|
|
||||||
c.pqi = append(c.pqi, x)
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *pollQueueSet) wakeForShutdown() error {
|
|
||||||
var buf [8]byte
|
|
||||||
binary.NativeEndian.PutUint64(buf[:], 1)
|
|
||||||
_, err := unix.Write(c.shutdownFd, buf[:])
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *pollQueueSet) Close() error {
|
|
||||||
if c.shutdownFd < 0 {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
errs := []error{}
|
|
||||||
|
|
||||||
if err := c.wakeForShutdown(); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, x := range c.pq {
|
|
||||||
if err := x.Close(); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// All Polls reference shutdownFd in their pollfd arrays, so close it
|
|
||||||
// only after every Poll.Close has returned.
|
|
||||||
if err := unix.Close(c.shutdownFd); err != nil {
|
|
||||||
errs = append(errs, err)
|
|
||||||
}
|
|
||||||
c.shutdownFd = -1
|
|
||||||
|
|
||||||
return errors.Join(errs...)
|
|
||||||
}
|
|
||||||
@@ -1,69 +0,0 @@
|
|||||||
//go:build linux && !android && !e2e_testing
|
|
||||||
|
|
||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
|
||||||
|
|
||||||
// fakeBatch stands in for batch.TxBatcher inside the bench — same shape
|
|
||||||
// of pointer-capturing closure that sendInsideMessage builds.
|
|
||||||
type fakeBatch struct{ buf [65536]byte }
|
|
||||||
|
|
||||||
func (b *fakeBatch) Reserve(sz int) []byte { return b.buf[:sz] }
|
|
||||||
func (b *fakeBatch) Commit([]byte) {}
|
|
||||||
|
|
||||||
type fakeHostInfo struct {
|
|
||||||
remoteIndexId uint32
|
|
||||||
counter uint64
|
|
||||||
}
|
|
||||||
type fakeIface struct {
|
|
||||||
rebindCount uint8
|
|
||||||
hi *fakeHostInfo
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkSegmentSuperpacketAllocsTSO measures allocation per
|
|
||||||
// PerSegment call when a closure captures pointer-bearing receivers — the
|
|
||||||
// realistic shape of sendInsideMessage's closure.
|
|
||||||
func BenchmarkSegmentSuperpacketAllocsTSO(b *testing.B) {
|
|
||||||
const mss = 1400
|
|
||||||
const numSeg = 32
|
|
||||||
pkt := buildTSOv6(mss*numSeg, mss)
|
|
||||||
gso := wire.GSOInfo{
|
|
||||||
Size: mss,
|
|
||||||
HdrLen: 60, // 40 (IPv6) + 20 (TCP)
|
|
||||||
CsumStart: 40,
|
|
||||||
Proto: wire.GSOProtoTCP,
|
|
||||||
}
|
|
||||||
p := wire.TunPacket{Bytes: pkt, Meta: gso}
|
|
||||||
|
|
||||||
hi := &fakeHostInfo{remoteIndexId: 0xdeadbeef}
|
|
||||||
f := &fakeIface{rebindCount: 7, hi: hi}
|
|
||||||
fb := &fakeBatch{}
|
|
||||||
|
|
||||||
// PerSegment consumes pkt destructively; refresh from a master copy
|
|
||||||
// each iter (matches the production pattern where every TUN read hands
|
|
||||||
// the segmenter a fresh kernel-supplied buffer).
|
|
||||||
master := append([]byte(nil), pkt...)
|
|
||||||
work := make([]byte, len(pkt))
|
|
||||||
p.Bytes = work
|
|
||||||
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
copy(work, master)
|
|
||||||
err := p.PerSegment(func(seg []byte) error {
|
|
||||||
out := fb.Reserve(16 + len(seg) + 16)
|
|
||||||
out[0] = byte(f.rebindCount)
|
|
||||||
out[1] = byte(hi.counter)
|
|
||||||
hi.counter++
|
|
||||||
fb.Commit(out)
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
b.Fatalf("PerSegment: %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,90 +0,0 @@
|
|||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
|
||||||
|
|
||||||
// QueueSet holds one or many Queue objects and helps close them in an orderly way.
|
|
||||||
type QueueSet interface {
|
|
||||||
io.Closer
|
|
||||||
Queues() []Queue
|
|
||||||
|
|
||||||
// Add takes a tun fd, adds it to the set, and prepares it for use as a Queue.
|
|
||||||
Add(fd int) error
|
|
||||||
}
|
|
||||||
|
|
||||||
// Capabilities advertises which kernel offload features a Queue successfully negotiated.
|
|
||||||
// Callers consult this to decide which coalescers to wire onto the write path.
|
|
||||||
type Capabilities struct {
|
|
||||||
// TSO means the FD was opened with IFF_VNET_HDR and the kernel agreed
|
|
||||||
// to TUN_F_TSO4|TSO6 — i.e. WriteGSO with GSOProtoTCP is safe.
|
|
||||||
TSO bool
|
|
||||||
// USO means the kernel additionally agreed to TUN_F_USO4|USO6, so
|
|
||||||
// WriteGSO with GSOProtoUDP is safe. Linux ≥ 6.2.
|
|
||||||
USO bool
|
|
||||||
}
|
|
||||||
|
|
||||||
// Queue is a readable/writable Poll queue. One Queue is driven by a single
|
|
||||||
// read goroutine plus a single writer (see Write below).
|
|
||||||
type Queue interface {
|
|
||||||
io.Closer
|
|
||||||
|
|
||||||
// Read will read at least 1 packet from the tun (up to len(p)).
|
|
||||||
// mem will be used to provide the backing for each of p[n].Bytes.
|
|
||||||
// Callers should size mem and p to avoid exhausting mem before p.
|
|
||||||
// Returns the number of packets actually read, or error.
|
|
||||||
Read(p []wire.TunPacket, mem []byte) (int, error)
|
|
||||||
|
|
||||||
// Write emits a single packet on the plaintext (outside→inside)
|
|
||||||
// delivery path.
|
|
||||||
Write(p []byte) (int, error)
|
|
||||||
|
|
||||||
// Capabilities returns the Queue's negotiated offload capabilities,
|
|
||||||
// or the zero value when q does not advertise any.
|
|
||||||
Capabilities() Capabilities
|
|
||||||
}
|
|
||||||
|
|
||||||
// GSOWriter is implemented by Queues that can emit a TCP or UDP superpacket
|
|
||||||
// assembled from a header prefix plus one or more borrowed payload
|
|
||||||
// fragments, in a single vectored write (writev with a leading
|
|
||||||
// virtio_net_hdr). This lets the coalescer avoid copying payload bytes
|
|
||||||
// between the caller's decrypt buffer and the TUN. Backends without GSO
|
|
||||||
// support do not implement this interface and coalescing is skipped.
|
|
||||||
//
|
|
||||||
// hdr contains the IPv4/IPv6 header prefix (mutable - callers will have
|
|
||||||
// filled in total length and IP csum). transportHdr is the TCP or UDP
|
|
||||||
// header (mutable - the L4 checksum field must hold the pseudo-header
|
|
||||||
// partial, single-fold not inverted, per virtio NEEDS_CSUM semantics).
|
|
||||||
// pays are non-overlapping payload fragments whose concatenation is the
|
|
||||||
// full superpacket payload; they are read-only from the writer's
|
|
||||||
// perspective and must remain valid until the call returns. Every segment
|
|
||||||
// in pays except possibly the last is exactly the same size. proto picks
|
|
||||||
// the L4 protocol so the writer knows which GSOType / CsumOffset to set.
|
|
||||||
//
|
|
||||||
// Callers should also consult Queue.Capabilities (via SupportsGSO) for
|
|
||||||
// the per-protocol negotiated capability; an implementation of GSOWriter
|
|
||||||
// is necessary but not sufficient since USO may not have been negotiated
|
|
||||||
// even when TSO was.
|
|
||||||
type GSOWriter interface {
|
|
||||||
WriteGSO(hdr []byte, transportHdr []byte, pays [][]byte, proto wire.GSOProto) error
|
|
||||||
}
|
|
||||||
|
|
||||||
// SupportsGSO reports whether w implements GSOWriter and the underlying
|
|
||||||
// queue advertises the negotiated capability for `want` via Capabilities.
|
|
||||||
func SupportsGSO(w Queue, want wire.GSOProto) (GSOWriter, bool) {
|
|
||||||
gw, ok := w.(GSOWriter)
|
|
||||||
if !ok {
|
|
||||||
return nil, false
|
|
||||||
}
|
|
||||||
caps := w.Capabilities()
|
|
||||||
switch want {
|
|
||||||
case wire.GSOProtoTCP:
|
|
||||||
return gw, caps.TSO
|
|
||||||
case wire.GSOProtoUDP:
|
|
||||||
return gw, caps.USO
|
|
||||||
default:
|
|
||||||
return gw, false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,447 +0,0 @@
|
|||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
|
||||||
"os"
|
|
||||||
"sync"
|
|
||||||
"sync/atomic"
|
|
||||||
"syscall"
|
|
||||||
"unsafe"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio/virtio"
|
|
||||||
)
|
|
||||||
|
|
||||||
// tunRxBufSize is the per-Read worst-case footprint for one kernel-supplied
|
|
||||||
// packet body, which is at most ~64 KiB (tunReadBufSize). Segmentation
|
|
||||||
// happens at encrypt time via wire.TunPacket.PerSegment on a per-routine
|
|
||||||
// MTU-sized scratch, so the caller-supplied read buffer only holds raw
|
|
||||||
// kernel-supplied bytes. Used by Read's drain loop to gate further reads
|
|
||||||
// on whether the remaining buffer can still hold one worst-case packet.
|
|
||||||
const tunRxBufSize = 64 * 1024
|
|
||||||
|
|
||||||
// gsoMaxIovs caps the iovec budget WriteGSO assembles per call: 3 fixed
|
|
||||||
// entries (virtio_net_hdr, IP hdr, transport hdr) plus up to gsoMaxIovs-3
|
|
||||||
// payload fragments. Sized comfortably above the typical kernel GSO
|
|
||||||
// segment cap (Linux UDP_GRO is 64) so realistic coalesced bursts never
|
|
||||||
// touch the limit. iovecs are tiny (16 bytes), so the entire scratch is
|
|
||||||
// 4 KiB — fine to keep resident on every queue. WriteGSO returns an error
|
|
||||||
// rather than reallocating when a caller exceeds this budget.
|
|
||||||
const gsoMaxIovs = 256
|
|
||||||
|
|
||||||
// validVnetHdr is the 10-byte virtio_net_hdr we prepend to every non-GSO TUN
|
|
||||||
// write. Only flag set is VIRTIO_NET_HDR_F_DATA_VALID, which marks the skb
|
|
||||||
// CHECKSUM_UNNECESSARY so the receiving network stack skips L4 checksum
|
|
||||||
// verification. All packets that reach the plain Write paths already carry
|
|
||||||
// a valid L4 checksum (either supplied by a remote peer whose ciphertext we
|
|
||||||
// AEAD-authenticated, produced by virtio.SegmentTCP/SegmentUDP during
|
|
||||||
// superpacket segmentation, or built locally by CreateRejectPacket), so
|
|
||||||
// trusting them is safe.
|
|
||||||
var validVnetHdr = [virtio.Size]byte{unix.VIRTIO_NET_HDR_F_DATA_VALID}
|
|
||||||
|
|
||||||
// Offload wraps a TUN file descriptor with poll-based reads. The FD provided will be changed to non-blocking.
|
|
||||||
// A shared eventfd allows Close to wake all readers blocked in poll.
|
|
||||||
type Offload struct {
|
|
||||||
fd int
|
|
||||||
shutdownFd int
|
|
||||||
readPoll [2]unix.PollFd
|
|
||||||
writePoll [2]unix.PollFd
|
|
||||||
// writeLock serializes blockOnWrite's read+clear of writePoll[*].Revents.
|
|
||||||
// Any goroutine that calls Write may end up parked in poll(2); without
|
|
||||||
// the lock concurrent waiters could race the Revents reset and lose
|
|
||||||
// events.
|
|
||||||
writeLock sync.Mutex
|
|
||||||
closed atomic.Bool
|
|
||||||
|
|
||||||
// readVnetScratch holds the 10-byte virtio_net_hdr split off the front of
|
|
||||||
// every TUN read via readv(2). Decoupling the header from the packet body
|
|
||||||
// lets us read the body directly into the caller-supplied mem at the
|
|
||||||
// current rxOff with no userspace copy on the GSO_NONE fast path.
|
|
||||||
readVnetScratch [virtio.Size]byte
|
|
||||||
// readIovs is the readv(2) iovec scratch wired once at construction —
|
|
||||||
// iovec[0] points at readVnetScratch; iovec[1].Base/Len is updated per
|
|
||||||
// read to address the caller-supplied mem slot.
|
|
||||||
readIovs [2]unix.Iovec
|
|
||||||
|
|
||||||
// usoEnabled records whether the kernel agreed to TUN_F_USO* on this FD,
|
|
||||||
// so writers can decide whether emitting GSO_UDP_L4 superpackets is safe.
|
|
||||||
usoEnabled bool
|
|
||||||
|
|
||||||
// gsoHdrBuf is a per-queue 10-byte scratch for the virtio_net_hdr emitted
|
|
||||||
// by WriteGSO. Kept separate from the read-only package-level validVnetHdr
|
|
||||||
// so non-GSO Writes can ship that constant directly while WriteGSO
|
|
||||||
// rewrites this scratch on every call.
|
|
||||||
gsoHdrBuf [virtio.Size]byte
|
|
||||||
// gsoIovs is the writev iovec scratch for WriteGSO. Pre-sized to
|
|
||||||
// gsoMaxIovs at construction; never grown. WriteGSO returns an error
|
|
||||||
// (and drops the call) if a caller hands it more fragments than fit.
|
|
||||||
gsoIovs []unix.Iovec
|
|
||||||
}
|
|
||||||
|
|
||||||
func newOffload(fd int, shutdownFd int, usoEnabled bool) (*Offload, error) {
|
|
||||||
if err := unix.SetNonblock(fd, true); err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to set tun fd non-blocking: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
out := &Offload{
|
|
||||||
fd: fd,
|
|
||||||
shutdownFd: shutdownFd,
|
|
||||||
usoEnabled: usoEnabled,
|
|
||||||
closed: atomic.Bool{},
|
|
||||||
readPoll: [2]unix.PollFd{
|
|
||||||
{Fd: int32(fd), Events: unix.POLLIN},
|
|
||||||
{Fd: int32(shutdownFd), Events: unix.POLLIN},
|
|
||||||
},
|
|
||||||
writePoll: [2]unix.PollFd{
|
|
||||||
{Fd: int32(fd), Events: unix.POLLOUT},
|
|
||||||
{Fd: int32(shutdownFd), Events: unix.POLLIN},
|
|
||||||
},
|
|
||||||
writeLock: sync.Mutex{},
|
|
||||||
gsoIovs: make([]unix.Iovec, 2, gsoMaxIovs),
|
|
||||||
}
|
|
||||||
|
|
||||||
out.gsoIovs[0].Base = &out.gsoHdrBuf[0]
|
|
||||||
out.gsoIovs[0].SetLen(virtio.Size)
|
|
||||||
|
|
||||||
// readIovs[0] is wired once to the virtio_net_hdr scratch; per-read we
|
|
||||||
// only repoint readIovs[1] at the next caller-supplied mem slot
|
|
||||||
// (see readPacket).
|
|
||||||
out.readIovs[0].Base = &out.readVnetScratch[0]
|
|
||||||
out.readIovs[0].SetLen(virtio.Size)
|
|
||||||
|
|
||||||
return out, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *Offload) blockOnRead() error {
|
|
||||||
const problemFlags = unix.POLLHUP | unix.POLLNVAL | unix.POLLERR
|
|
||||||
var err error
|
|
||||||
for {
|
|
||||||
_, err = unix.Poll(r.readPoll[:], -1)
|
|
||||||
if err != unix.EINTR {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
//always reset these!
|
|
||||||
tunEvents := r.readPoll[0].Revents
|
|
||||||
shutdownEvents := r.readPoll[1].Revents
|
|
||||||
r.readPoll[0].Revents = 0
|
|
||||||
r.readPoll[1].Revents = 0
|
|
||||||
//do the err check before trusting the potentially bogus bits we just got
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if shutdownEvents&(unix.POLLIN|problemFlags) != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
} else if tunEvents&problemFlags != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *Offload) blockOnWrite() error {
|
|
||||||
const problemFlags = unix.POLLHUP | unix.POLLNVAL | unix.POLLERR
|
|
||||||
var err error
|
|
||||||
for {
|
|
||||||
_, err = unix.Poll(r.writePoll[:], -1)
|
|
||||||
if err != unix.EINTR {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
//always reset these!
|
|
||||||
r.writeLock.Lock()
|
|
||||||
tunEvents := r.writePoll[0].Revents
|
|
||||||
shutdownEvents := r.writePoll[1].Revents
|
|
||||||
r.writePoll[0].Revents = 0
|
|
||||||
r.writePoll[1].Revents = 0
|
|
||||||
r.writeLock.Unlock()
|
|
||||||
//do the err check before trusting the potentially bogus bits we just got
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if shutdownEvents&(unix.POLLIN|problemFlags) != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
} else if tunEvents&problemFlags != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// readPacket issues a single readv(2) splitting the virtio_net_hdr off
|
|
||||||
// into readVnetScratch and reading the packet body directly into mem.
|
|
||||||
// Returns the body length (zero virtio header bytes, just the IP
|
|
||||||
// packet/superpacket). block controls whether EAGAIN is retried via poll:
|
|
||||||
// the initial read of a drain blocks; subsequent drain reads do not.
|
|
||||||
//
|
|
||||||
// The body iovec capacity is always tunReadBufSize; the Read drain loop
|
|
||||||
// gates entry on len(mem)-rxOff >= tunRxBufSize, sized to hold one
|
|
||||||
// worst-case kernel-supplied packet body. Without that gate the body
|
|
||||||
// iovec could be smaller than the next inbound packet and the kernel
|
|
||||||
// would truncate.
|
|
||||||
func (r *Offload) readPacket(mem []byte, block bool) (int, error) {
|
|
||||||
for {
|
|
||||||
r.readIovs[1].Base = &mem[0]
|
|
||||||
r.readIovs[1].SetLen(tunReadBufSize)
|
|
||||||
n, _, errno := syscall.Syscall(unix.SYS_READV, uintptr(r.fd), uintptr(unsafe.Pointer(&r.readIovs[0])), uintptr(len(r.readIovs)))
|
|
||||||
if errno == 0 {
|
|
||||||
if int(n) < virtio.Size {
|
|
||||||
return 0, io.ErrShortWrite
|
|
||||||
}
|
|
||||||
return int(n) - virtio.Size, nil
|
|
||||||
}
|
|
||||||
if errno == unix.EAGAIN {
|
|
||||||
if !block {
|
|
||||||
return 0, errno
|
|
||||||
}
|
|
||||||
if err := r.blockOnRead(); err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if errno == unix.EINTR {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if errno == unix.EBADF {
|
|
||||||
return 0, os.ErrClosed
|
|
||||||
}
|
|
||||||
return 0, errno
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Read returns one or more packets from the tun. Each wire.TunPacket
|
|
||||||
// either carries a single ready-to-use IP datagram (GSO zero) or a TSO/USO
|
|
||||||
// superpacket plus the wire.GSOInfo a caller needs to segment it (see
|
|
||||||
// wire.TunPacket.PerSegment). The first read blocks via poll; once the fd
|
|
||||||
// is known readable we drain additional packets non-blocking until the
|
|
||||||
// kernel queue is empty (EAGAIN), p is full, or mem no longer has room
|
|
||||||
// for another worst-case packet (tunRxBufSize). This amortizes the poll
|
|
||||||
// wake over bursts of small packets (e.g. TCP ACKs). The Bytes slices on
|
|
||||||
// returned packets point into the caller-supplied mem and are only valid
|
|
||||||
// until the next Read or Close on this Queue.
|
|
||||||
func (r *Offload) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
maxP := len(p)
|
|
||||||
maxM := len(mem)
|
|
||||||
p = p[:0]
|
|
||||||
rxOff := 0
|
|
||||||
|
|
||||||
// Initial (blocking) read. Retry on decode errors so a single bad
|
|
||||||
// packet does not stall the reader.
|
|
||||||
for {
|
|
||||||
n, err := r.readPacket(mem, true)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
if p, err = r.decodeRead(p, mem, n); err != nil {
|
|
||||||
// Drop and read again — a bad packet should not kill the reader.
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
rxOff += n
|
|
||||||
break
|
|
||||||
}
|
|
||||||
|
|
||||||
// Drain: non-blocking reads until the kernel queue is empty, p is full,
|
|
||||||
// or mem no longer has room for another worst-case kernel-supplied
|
|
||||||
// packet (tunRxBufSize).
|
|
||||||
for len(p) < maxP && maxM-rxOff >= tunRxBufSize {
|
|
||||||
n, err := r.readPacket(mem[rxOff:], false)
|
|
||||||
if err != nil {
|
|
||||||
// EAGAIN / EINTR / anything else: stop draining. We already
|
|
||||||
// have a valid batch from the first read.
|
|
||||||
break
|
|
||||||
}
|
|
||||||
if n <= 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
if p, err = r.decodeRead(p, mem[rxOff:], n); err != nil {
|
|
||||||
// Drop this packet and stop the drain; we'd rather hand off
|
|
||||||
// what we have than keep spinning here.
|
|
||||||
break
|
|
||||||
}
|
|
||||||
rxOff += n
|
|
||||||
}
|
|
||||||
|
|
||||||
return len(p), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// decodeRead processes the packet sitting at mem[:pktLen]. The bytes stay
|
|
||||||
// in mem — for GSO_NONE we slice them as a regular IP datagram (running
|
|
||||||
// finishChecksum if NEEDS_CSUM is set); for TSO/USO superpackets we attach
|
|
||||||
// the corrected GSO metadata so the caller can segment lazily at encrypt
|
|
||||||
// time. The caller advances its own rxOff past the kernel-supplied body
|
|
||||||
// and nothing else, since segmentation no longer writes back into mem.
|
|
||||||
func (r *Offload) decodeRead(p []wire.TunPacket, mem []byte, pktLen int) ([]wire.TunPacket, error) {
|
|
||||||
if pktLen <= 0 {
|
|
||||||
return p, fmt.Errorf("short tun read: %d", pktLen)
|
|
||||||
}
|
|
||||||
var hdr virtio.Hdr
|
|
||||||
hdr.Decode(r.readVnetScratch[:])
|
|
||||||
|
|
||||||
body := mem[:pktLen]
|
|
||||||
|
|
||||||
if hdr.GSOType == unix.VIRTIO_NET_HDR_GSO_NONE {
|
|
||||||
if hdr.Flags&unix.VIRTIO_NET_HDR_F_NEEDS_CSUM != 0 {
|
|
||||||
if err := virtio.FinishChecksum(body, hdr); err != nil {
|
|
||||||
return p, err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
p = append(p, wire.TunPacket{Bytes: body})
|
|
||||||
return p, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// GSO superpacket: validate, fix the kernel-supplied HdrLen on the
|
|
||||||
// FORWARD path (CorrectHdrLen), pick the L4 protocol, and attach
|
|
||||||
// the metadata. The bytes stay in mem untouched; segmentation
|
|
||||||
// happens in wire.TunPacket.PerSegment at encrypt time.
|
|
||||||
if err := virtio.CheckValid(body, hdr); err != nil {
|
|
||||||
return p, err
|
|
||||||
}
|
|
||||||
if err := virtio.CorrectHdrLen(body, &hdr); err != nil {
|
|
||||||
return p, err
|
|
||||||
}
|
|
||||||
proto, err := protoFromGSOType(hdr.GSOType)
|
|
||||||
if err != nil {
|
|
||||||
return p, err
|
|
||||||
}
|
|
||||||
p = append(p, wire.TunPacket{
|
|
||||||
Bytes: body,
|
|
||||||
Meta: wire.GSOInfo{
|
|
||||||
Size: hdr.GSOSize,
|
|
||||||
HdrLen: hdr.HdrLen,
|
|
||||||
CsumStart: hdr.CsumStart,
|
|
||||||
Proto: proto,
|
|
||||||
},
|
|
||||||
})
|
|
||||||
return p, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *Offload) Write(buf []byte) (int, error) {
|
|
||||||
iovs := [2]unix.Iovec{
|
|
||||||
{Base: &validVnetHdr[0]},
|
|
||||||
{Base: &buf[0]},
|
|
||||||
}
|
|
||||||
iovs[0].SetLen(virtio.Size)
|
|
||||||
iovs[1].SetLen(len(buf))
|
|
||||||
return r.writeWithScratch(buf, &iovs)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *Offload) writeWithScratch(buf []byte, iovs *[2]unix.Iovec) (int, error) {
|
|
||||||
if len(buf) == 0 {
|
|
||||||
return 0, nil
|
|
||||||
}
|
|
||||||
iovs[1].Base = &buf[0]
|
|
||||||
iovs[1].SetLen(len(buf))
|
|
||||||
return r.rawWrite(unsafe.Slice(&iovs[0], len(iovs)))
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *Offload) rawWrite(iovs []unix.Iovec) (int, error) {
|
|
||||||
for {
|
|
||||||
n, _, errno := syscall.Syscall(unix.SYS_WRITEV, uintptr(r.fd), uintptr(unsafe.Pointer(&iovs[0])), uintptr(len(iovs)))
|
|
||||||
if errno == 0 {
|
|
||||||
if int(n) < virtio.Size {
|
|
||||||
return 0, io.ErrShortWrite
|
|
||||||
}
|
|
||||||
return int(n) - virtio.Size, nil
|
|
||||||
}
|
|
||||||
if errno == unix.EAGAIN {
|
|
||||||
if err := r.blockOnWrite(); err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if errno == unix.EINTR {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if errno == unix.EBADF {
|
|
||||||
return 0, os.ErrClosed
|
|
||||||
}
|
|
||||||
return 0, errno
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Capabilities reports the offload features negotiated for this Queue. TSO
|
|
||||||
// is always true for Offload (we only construct it on IFF_VNET_HDR FDs);
|
|
||||||
// USO is true only when the kernel agreed to TUN_F_USO4|6 at open time
|
|
||||||
// (Linux ≥ 6.2).
|
|
||||||
func (r *Offload) Capabilities() Capabilities {
|
|
||||||
return Capabilities{TSO: true, USO: r.usoEnabled}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *Offload) WriteGSO(hdr []byte, transportHdr []byte, pays [][]byte, proto wire.GSOProto) error {
|
|
||||||
if len(hdr) == 0 || len(pays) == 0 || len(transportHdr) == 0 {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
// L4 checksum offset inside transportHdr: TCP=16 (the `check` field after
|
|
||||||
// seq/ack/dataoff/flags/window), UDP=6 (after sport/dport/length).
|
|
||||||
var csumOff uint16
|
|
||||||
switch proto {
|
|
||||||
case wire.GSOProtoUDP:
|
|
||||||
csumOff = 6
|
|
||||||
default:
|
|
||||||
csumOff = 16
|
|
||||||
}
|
|
||||||
vhdr := virtio.Hdr{
|
|
||||||
Flags: unix.VIRTIO_NET_HDR_F_NEEDS_CSUM,
|
|
||||||
HdrLen: uint16(len(hdr) + len(transportHdr)),
|
|
||||||
GSOSize: uint16(len(pays[0])),
|
|
||||||
CsumStart: uint16(len(hdr)),
|
|
||||||
CsumOffset: csumOff,
|
|
||||||
}
|
|
||||||
if len(pays) > 1 {
|
|
||||||
ipVer := hdr[0] >> 4
|
|
||||||
switch {
|
|
||||||
case proto == wire.GSOProtoUDP && (ipVer == 4 || ipVer == 6):
|
|
||||||
vhdr.GSOType = unix.VIRTIO_NET_HDR_GSO_UDP_L4
|
|
||||||
case ipVer == 6:
|
|
||||||
vhdr.GSOType = unix.VIRTIO_NET_HDR_GSO_TCPV6
|
|
||||||
case ipVer == 4:
|
|
||||||
vhdr.GSOType = unix.VIRTIO_NET_HDR_GSO_TCPV4
|
|
||||||
default:
|
|
||||||
vhdr.GSOType = unix.VIRTIO_NET_HDR_GSO_NONE
|
|
||||||
vhdr.GSOSize = 0
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
vhdr.GSOType = unix.VIRTIO_NET_HDR_GSO_NONE
|
|
||||||
vhdr.GSOSize = 0
|
|
||||||
}
|
|
||||||
vhdr.Encode(r.gsoHdrBuf[:])
|
|
||||||
|
|
||||||
// Build the iovec array: [virtio_hdr, hdr, transportHdr, pays...]. r.gsoIovs[0] is
|
|
||||||
// wired to gsoHdrBuf at construction and never changes.
|
|
||||||
need := 3 + len(pays)
|
|
||||||
if need > cap(r.gsoIovs) {
|
|
||||||
slog.Default().Warn("tio: WriteGSO iovec budget exceeded; dropping superpacket",
|
|
||||||
"need", need, "cap", cap(r.gsoIovs), "segments", len(pays))
|
|
||||||
return fmt.Errorf("tio: WriteGSO needs %d iovecs but cap is %d", need, cap(r.gsoIovs))
|
|
||||||
}
|
|
||||||
r.gsoIovs = r.gsoIovs[:need]
|
|
||||||
r.gsoIovs[1].Base = &hdr[0]
|
|
||||||
r.gsoIovs[1].SetLen(len(hdr))
|
|
||||||
r.gsoIovs[2].Base = &transportHdr[0]
|
|
||||||
r.gsoIovs[2].SetLen(len(transportHdr))
|
|
||||||
for i, p := range pays {
|
|
||||||
r.gsoIovs[3+i].Base = &p[0]
|
|
||||||
r.gsoIovs[3+i].SetLen(len(p))
|
|
||||||
}
|
|
||||||
|
|
||||||
_, err := r.rawWrite(r.gsoIovs)
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *Offload) Close() error {
|
|
||||||
if r.closed.Swap(true) {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
//shutdownFd is owned by the container, so we should not close it
|
|
||||||
var err error
|
|
||||||
if r.fd >= 0 {
|
|
||||||
err = unix.Close(r.fd)
|
|
||||||
r.fd = -1
|
|
||||||
}
|
|
||||||
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
@@ -1,169 +0,0 @@
|
|||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"os"
|
|
||||||
"sync/atomic"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Maximum size we accept for a single read from a TUN with IFF_VNET_HDR. A
|
|
||||||
// TSO superpacket can be up to 64KiB of payload plus a single L2/L3/L4 header
|
|
||||||
// prefix plus the virtio header.
|
|
||||||
const tunReadBufSize = 65535
|
|
||||||
|
|
||||||
type Poll struct {
|
|
||||||
fd int
|
|
||||||
|
|
||||||
readPoll [2]unix.PollFd
|
|
||||||
writePoll [2]unix.PollFd
|
|
||||||
closed atomic.Bool
|
|
||||||
}
|
|
||||||
|
|
||||||
func newPoll(fd int, shutdownFd int) (*Poll, error) {
|
|
||||||
if err := unix.SetNonblock(fd, true); err != nil {
|
|
||||||
_ = unix.Close(fd)
|
|
||||||
return nil, fmt.Errorf("failed to set Poll device as nonblocking: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
out := &Poll{
|
|
||||||
fd: fd,
|
|
||||||
readPoll: [2]unix.PollFd{
|
|
||||||
{Fd: int32(fd), Events: unix.POLLIN},
|
|
||||||
{Fd: int32(shutdownFd), Events: unix.POLLIN},
|
|
||||||
},
|
|
||||||
writePoll: [2]unix.PollFd{
|
|
||||||
{Fd: int32(fd), Events: unix.POLLOUT},
|
|
||||||
{Fd: int32(shutdownFd), Events: unix.POLLIN},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
return out, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// blockOnRead waits until the Poll fd is readable or shutdown has been signaled.
|
|
||||||
// Returns os.ErrClosed if Close was called.
|
|
||||||
func (t *Poll) blockOnRead() error {
|
|
||||||
const problemFlags = unix.POLLHUP | unix.POLLNVAL | unix.POLLERR
|
|
||||||
var err error
|
|
||||||
for {
|
|
||||||
_, err = unix.Poll(t.readPoll[:], -1)
|
|
||||||
if err != unix.EINTR {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
tunEvents := t.readPoll[0].Revents
|
|
||||||
shutdownEvents := t.readPoll[1].Revents
|
|
||||||
t.readPoll[0].Revents = 0
|
|
||||||
t.readPoll[1].Revents = 0
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if shutdownEvents&(unix.POLLIN|problemFlags) != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
}
|
|
||||||
if tunEvents&problemFlags != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *Poll) blockOnWrite() error {
|
|
||||||
const problemFlags = unix.POLLHUP | unix.POLLNVAL | unix.POLLERR
|
|
||||||
var err error
|
|
||||||
for {
|
|
||||||
_, err = unix.Poll(t.writePoll[:], -1)
|
|
||||||
if err != unix.EINTR {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
tunEvents := t.writePoll[0].Revents
|
|
||||||
shutdownEvents := t.writePoll[1].Revents
|
|
||||||
t.writePoll[0].Revents = 0
|
|
||||||
t.writePoll[1].Revents = 0
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if shutdownEvents&(unix.POLLIN|problemFlags) != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
}
|
|
||||||
if tunEvents&problemFlags != 0 {
|
|
||||||
return os.ErrClosed
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *Poll) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = wire.GSOInfo{}
|
|
||||||
n, err := t.readOne(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *Poll) readOne(to []byte) (int, error) {
|
|
||||||
for {
|
|
||||||
n, errno := unix.Read(t.fd, to)
|
|
||||||
if errno == nil {
|
|
||||||
return n, nil
|
|
||||||
}
|
|
||||||
switch errno {
|
|
||||||
case unix.EAGAIN:
|
|
||||||
if err := t.blockOnRead(); err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
case unix.EINTR:
|
|
||||||
// retry
|
|
||||||
case unix.EBADF:
|
|
||||||
return 0, os.ErrClosed
|
|
||||||
default:
|
|
||||||
return 0, errno
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Write is only valid for single threaded use
|
|
||||||
func (t *Poll) Write(from []byte) (int, error) {
|
|
||||||
for {
|
|
||||||
n, errno := unix.Write(t.fd, from)
|
|
||||||
if errno == nil {
|
|
||||||
return n, nil
|
|
||||||
}
|
|
||||||
switch errno {
|
|
||||||
case unix.EAGAIN:
|
|
||||||
if err := t.blockOnWrite(); err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
case unix.EINTR:
|
|
||||||
// retry
|
|
||||||
case unix.EBADF:
|
|
||||||
return 0, os.ErrClosed
|
|
||||||
default:
|
|
||||||
return 0, errno
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *Poll) Close() error {
|
|
||||||
if t.closed.Swap(true) {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
//shutdownFd is owned by the container, so we should not close it
|
|
||||||
var err error
|
|
||||||
if t.fd >= 0 {
|
|
||||||
err = unix.Close(t.fd)
|
|
||||||
t.fd = -1
|
|
||||||
}
|
|
||||||
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *Poll) Capabilities() Capabilities {
|
|
||||||
return Capabilities{}
|
|
||||||
}
|
|
||||||
@@ -1,106 +0,0 @@
|
|||||||
//go:build linux && !android && !e2e_testing
|
|
||||||
// +build linux,!android,!e2e_testing
|
|
||||||
|
|
||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"os"
|
|
||||||
"sync"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
)
|
|
||||||
|
|
||||||
// newReadPipe returns a read fd. The matching write fd is registered for cleanup.
|
|
||||||
// The caller takes ownership of the read fd (pass it into a QueueSet).
|
|
||||||
func newReadPipe(t *testing.T) int {
|
|
||||||
t.Helper()
|
|
||||||
var fds [2]int
|
|
||||||
if err := unix.Pipe2(fds[:], unix.O_CLOEXEC); err != nil {
|
|
||||||
t.Fatalf("pipe2: %v", err)
|
|
||||||
}
|
|
||||||
t.Cleanup(func() { _ = unix.Close(fds[1]) })
|
|
||||||
return fds[0]
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestPoll_WakeForShutdown_WakesFriends(t *testing.T) {
|
|
||||||
parent, err := NewPollQueueSet()
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.NoError(t, parent.Add(newReadPipe(t)))
|
|
||||||
require.NoError(t, parent.Add(newReadPipe(t)))
|
|
||||||
// QueueSet.Close owns the read fds we Added — don't register a separate
|
|
||||||
// Cleanup to close them or we'll double-close whatever fd the kernel
|
|
||||||
// has since reused.
|
|
||||||
|
|
||||||
readers := parent.Queues()
|
|
||||||
errs := make([]error, len(readers))
|
|
||||||
var wg sync.WaitGroup
|
|
||||||
for i, r := range readers {
|
|
||||||
wg.Add(1)
|
|
||||||
go func(i int, r Queue) {
|
|
||||||
defer wg.Done()
|
|
||||||
pkts := make([]wire.TunPacket, 1)
|
|
||||||
_, errs[i] = r.Read(pkts, make([]byte, 64))
|
|
||||||
}(i, r)
|
|
||||||
}
|
|
||||||
|
|
||||||
time.Sleep(50 * time.Millisecond)
|
|
||||||
|
|
||||||
if err := parent.Close(); err != nil {
|
|
||||||
t.Fatalf("Close: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
done := make(chan struct{})
|
|
||||||
go func() { wg.Wait(); close(done) }()
|
|
||||||
select {
|
|
||||||
case <-done:
|
|
||||||
case <-time.After(2 * time.Second):
|
|
||||||
t.Fatal("readers did not wake")
|
|
||||||
}
|
|
||||||
|
|
||||||
for i, err := range errs {
|
|
||||||
if !errors.Is(err, os.ErrClosed) {
|
|
||||||
t.Errorf("reader %d: expected os.ErrClosed, got %v", i, err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestPoll_Close_Idempotent(t *testing.T) {
|
|
||||||
shutdownFd, err := unix.Eventfd(0, unix.EFD_NONBLOCK|unix.EFD_CLOEXEC)
|
|
||||||
require.NoError(t, err)
|
|
||||||
t.Cleanup(func() { _ = unix.Close(shutdownFd) })
|
|
||||||
|
|
||||||
tf, err := newPoll(newReadPipe(t), shutdownFd)
|
|
||||||
require.NoError(t, err)
|
|
||||||
if err := tf.Close(); err != nil {
|
|
||||||
t.Fatalf("first Close: %v", err)
|
|
||||||
}
|
|
||||||
if err := tf.Close(); err != nil {
|
|
||||||
t.Fatalf("second Close should be a no-op, got %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestPollQueueSet_Close_ClosesEventfd(t *testing.T) {
|
|
||||||
qs, err := NewPollQueueSet()
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.NoError(t, qs.Add(newReadPipe(t)))
|
|
||||||
|
|
||||||
fd := qs.(*pollQueueSet).shutdownFd
|
|
||||||
require.NoError(t, qs.Close())
|
|
||||||
|
|
||||||
// Closing the eventfd again should fail with EBADF, proving Close
|
|
||||||
// actually released it.
|
|
||||||
if err := unix.Close(fd); err == nil {
|
|
||||||
t.Fatalf("eventfd %d still open after QueueSet.Close", fd)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Second Close must be a no-op (and must not double-close the eventfd
|
|
||||||
// in case the kernel handed it out to another caller in the meantime).
|
|
||||||
if err := qs.Close(); err != nil {
|
|
||||||
t.Fatalf("second Close: %v", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
//go:build linux && !android && !e2e_testing
|
|
||||||
// +build linux,!android,!e2e_testing
|
|
||||||
|
|
||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
)
|
|
||||||
|
|
||||||
// protoFromGSOType maps a virtio_net_hdr GSOType to the GSOProto value the
|
|
||||||
// segment-time helpers use. Returns an error for GSO_NONE or any unknown
|
|
||||||
// value — the caller should only invoke this on a confirmed superpacket.
|
|
||||||
func protoFromGSOType(t uint8) (wire.GSOProto, error) {
|
|
||||||
switch t {
|
|
||||||
case unix.VIRTIO_NET_HDR_GSO_TCPV4, unix.VIRTIO_NET_HDR_GSO_TCPV6:
|
|
||||||
return wire.GSOProtoTCP, nil
|
|
||||||
case unix.VIRTIO_NET_HDR_GSO_UDP_L4:
|
|
||||||
return wire.GSOProtoUDP, nil
|
|
||||||
default:
|
|
||||||
return 0, fmt.Errorf("unsupported virtio gso type: %d", t)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,782 +0,0 @@
|
|||||||
//go:build linux && !android && !e2e_testing
|
|
||||||
// +build linux,!android,!e2e_testing
|
|
||||||
|
|
||||||
package tio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"os"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
"gvisor.dev/gvisor/pkg/tcpip/checksum"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/tio/virtio"
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
|
||||||
|
|
||||||
// testSegScratchSize is a generous segmentation scratch sized to fit any
|
|
||||||
// of the synthetic TSO/USO superpackets these tests generate (one
|
|
||||||
// worst-case 64 KiB superpacket plus replicated per-segment headers).
|
|
||||||
const testSegScratchSize = 192 * 1024
|
|
||||||
|
|
||||||
// verifyChecksum confirms that the one's-complement sum across `b`, seeded
|
|
||||||
// with a folded pseudo-header sum, equals all-ones (valid).
|
|
||||||
func verifyChecksum(b []byte, pseudo uint16) bool {
|
|
||||||
return checksum.Checksum(b, pseudo) == 0xffff
|
|
||||||
}
|
|
||||||
|
|
||||||
// segmentForTest is the test-only counterpart to the production
|
|
||||||
// wire.TunPacket.PerSegment path. It handles GSO_NONE (with optional
|
|
||||||
// finishChecksum) inline and dispatches GSO superpackets through
|
|
||||||
// PerSegment, draining each yielded segment into a freshly-copied [][]byte
|
|
||||||
// slot so callers can iterate after the call returns. Tests pre-set
|
|
||||||
// hdr.HdrLen correctly, so correctHdrLen is not invoked here.
|
|
||||||
func segmentForTest(pkt []byte, hdr virtio.Hdr, out *[][]byte, scratch []byte) error {
|
|
||||||
if hdr.GSOType == unix.VIRTIO_NET_HDR_GSO_NONE {
|
|
||||||
cp := append([]byte(nil), pkt...)
|
|
||||||
if hdr.Flags&unix.VIRTIO_NET_HDR_F_NEEDS_CSUM != 0 {
|
|
||||||
if err := virtio.FinishChecksum(cp, hdr); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
*out = append(*out, cp)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
proto, err := protoFromGSOType(hdr.GSOType)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
p := wire.TunPacket{
|
|
||||||
Bytes: pkt,
|
|
||||||
Meta: wire.GSOInfo{
|
|
||||||
Size: hdr.GSOSize,
|
|
||||||
HdrLen: hdr.HdrLen,
|
|
||||||
CsumStart: hdr.CsumStart,
|
|
||||||
Proto: proto,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
return p.PerSegment(func(seg []byte) error {
|
|
||||||
*out = append(*out, append([]byte(nil), seg...))
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
// pseudoHeaderIPv4 returns the folded pseudo-header sum used to verify a
|
|
||||||
// TCP/UDP segment's checksum in tests. src/dst are 4 bytes each.
|
|
||||||
func pseudoHeaderIPv4(src, dst []byte, proto byte, l4Len int) uint16 {
|
|
||||||
s := uint32(checksum.Checksum(src, 0)) + uint32(checksum.Checksum(dst, 0))
|
|
||||||
s += uint32(proto) + uint32(l4Len)
|
|
||||||
s = (s & 0xffff) + (s >> 16)
|
|
||||||
s = (s & 0xffff) + (s >> 16)
|
|
||||||
return uint16(s)
|
|
||||||
}
|
|
||||||
|
|
||||||
// pseudoHeaderIPv6 returns the folded pseudo-header sum used to verify a
|
|
||||||
// TCP/UDP segment's checksum in tests. src/dst are 16 bytes each.
|
|
||||||
func pseudoHeaderIPv6(src, dst []byte, proto byte, l4Len int) uint16 {
|
|
||||||
s := uint32(checksum.Checksum(src, 0)) + uint32(checksum.Checksum(dst, 0))
|
|
||||||
s += uint32(l4Len>>16) + uint32(l4Len&0xffff) + uint32(proto)
|
|
||||||
s = (s & 0xffff) + (s >> 16)
|
|
||||||
s = (s & 0xffff) + (s >> 16)
|
|
||||||
return uint16(s)
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildTSOv4 builds a synthetic IPv4/TCP TSO superpacket with a payload of
|
|
||||||
// `payLen` bytes split at `mss`.
|
|
||||||
func buildTSOv4(t *testing.T, payLen, mss int) ([]byte, virtio.Hdr) {
|
|
||||||
t.Helper()
|
|
||||||
const ipLen = 20
|
|
||||||
const tcpLen = 20
|
|
||||||
pkt := make([]byte, ipLen+tcpLen+payLen)
|
|
||||||
|
|
||||||
// IPv4 header
|
|
||||||
pkt[0] = 0x45 // version 4, IHL 5
|
|
||||||
// total length is meaningless for TSO but set it anyway
|
|
||||||
binary.BigEndian.PutUint16(pkt[2:4], uint16(ipLen+tcpLen+payLen))
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], 0x4242) // original ID
|
|
||||||
pkt[8] = 64 // TTL
|
|
||||||
pkt[9] = unix.IPPROTO_TCP
|
|
||||||
copy(pkt[12:16], []byte{10, 0, 0, 1}) // src
|
|
||||||
copy(pkt[16:20], []byte{10, 0, 0, 2}) // dst
|
|
||||||
|
|
||||||
// TCP header
|
|
||||||
binary.BigEndian.PutUint16(pkt[20:22], 12345) // sport
|
|
||||||
binary.BigEndian.PutUint16(pkt[22:24], 80) // dport
|
|
||||||
binary.BigEndian.PutUint32(pkt[24:28], 10000) // seq
|
|
||||||
binary.BigEndian.PutUint32(pkt[28:32], 20000) // ack
|
|
||||||
pkt[32] = 0x50 // data offset 5 words
|
|
||||||
pkt[33] = 0x18 // ACK | PSH
|
|
||||||
binary.BigEndian.PutUint16(pkt[34:36], 65535) // window
|
|
||||||
|
|
||||||
// payload
|
|
||||||
for i := 0; i < payLen; i++ {
|
|
||||||
pkt[ipLen+tcpLen+i] = byte(i & 0xff)
|
|
||||||
}
|
|
||||||
|
|
||||||
return pkt, virtio.Hdr{
|
|
||||||
Flags: unix.VIRTIO_NET_HDR_F_NEEDS_CSUM,
|
|
||||||
GSOType: unix.VIRTIO_NET_HDR_GSO_TCPV4,
|
|
||||||
HdrLen: uint16(ipLen + tcpLen),
|
|
||||||
GSOSize: uint16(mss),
|
|
||||||
CsumStart: uint16(ipLen),
|
|
||||||
CsumOffset: 16,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSegmentTCPv4(t *testing.T) {
|
|
||||||
const mss = 100
|
|
||||||
const numSeg = 3
|
|
||||||
pkt, hdr := buildTSOv4(t, mss*numSeg, mss)
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != numSeg {
|
|
||||||
t.Fatalf("expected %d segments, got %d", numSeg, len(out))
|
|
||||||
}
|
|
||||||
|
|
||||||
for i, seg := range out {
|
|
||||||
if len(seg) != 40+mss {
|
|
||||||
t.Errorf("seg %d: unexpected len %d", i, len(seg))
|
|
||||||
}
|
|
||||||
totalLen := binary.BigEndian.Uint16(seg[2:4])
|
|
||||||
if totalLen != uint16(40+mss) {
|
|
||||||
t.Errorf("seg %d: total_len=%d want %d", i, totalLen, 40+mss)
|
|
||||||
}
|
|
||||||
id := binary.BigEndian.Uint16(seg[4:6])
|
|
||||||
if id != 0x4242+uint16(i) {
|
|
||||||
t.Errorf("seg %d: ip id=%#x want %#x", i, id, 0x4242+uint16(i))
|
|
||||||
}
|
|
||||||
seq := binary.BigEndian.Uint32(seg[24:28])
|
|
||||||
wantSeq := uint32(10000 + i*mss)
|
|
||||||
if seq != wantSeq {
|
|
||||||
t.Errorf("seg %d: seq=%d want %d", i, seq, wantSeq)
|
|
||||||
}
|
|
||||||
flags := seg[33]
|
|
||||||
wantFlags := byte(0x10) // ACK only, PSH cleared
|
|
||||||
if i == numSeg-1 {
|
|
||||||
wantFlags = 0x18 // ACK | PSH preserved on last
|
|
||||||
}
|
|
||||||
if flags != wantFlags {
|
|
||||||
t.Errorf("seg %d: flags=%#x want %#x", i, flags, wantFlags)
|
|
||||||
}
|
|
||||||
// IPv4 header checksum must verify against itself.
|
|
||||||
if !verifyChecksum(seg[:20], 0) {
|
|
||||||
t.Errorf("seg %d: bad IPv4 header checksum", i)
|
|
||||||
}
|
|
||||||
// TCP checksum must verify against the pseudo-header.
|
|
||||||
psum := pseudoHeaderIPv4(seg[12:16], seg[16:20], unix.IPPROTO_TCP, 20+mss)
|
|
||||||
if !verifyChecksum(seg[20:], psum) {
|
|
||||||
t.Errorf("seg %d: bad TCP checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSegmentTCPv4OddTail(t *testing.T) {
|
|
||||||
// Payload of 250 bytes with MSS 100 → segments of 100, 100, 50.
|
|
||||||
pkt, hdr := buildTSOv4(t, 250, 100)
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != 3 {
|
|
||||||
t.Fatalf("want 3 segments, got %d", len(out))
|
|
||||||
}
|
|
||||||
wantPayLens := []int{100, 100, 50}
|
|
||||||
for i, seg := range out {
|
|
||||||
if len(seg)-40 != wantPayLens[i] {
|
|
||||||
t.Errorf("seg %d: pay len %d want %d", i, len(seg)-40, wantPayLens[i])
|
|
||||||
}
|
|
||||||
if !verifyChecksum(seg[:20], 0) {
|
|
||||||
t.Errorf("seg %d: bad IPv4 header checksum", i)
|
|
||||||
}
|
|
||||||
psum := pseudoHeaderIPv4(seg[12:16], seg[16:20], unix.IPPROTO_TCP, 20+wantPayLens[i])
|
|
||||||
if !verifyChecksum(seg[20:], psum) {
|
|
||||||
t.Errorf("seg %d: bad TCP checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSegmentTCPv6(t *testing.T) {
|
|
||||||
const ipLen = 40
|
|
||||||
const tcpLen = 20
|
|
||||||
const mss = 120
|
|
||||||
const numSeg = 2
|
|
||||||
payLen := mss * numSeg
|
|
||||||
pkt := make([]byte, ipLen+tcpLen+payLen)
|
|
||||||
|
|
||||||
// IPv6 header
|
|
||||||
pkt[0] = 0x60 // version 6
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], uint16(tcpLen+payLen))
|
|
||||||
pkt[6] = unix.IPPROTO_TCP
|
|
||||||
pkt[7] = 64
|
|
||||||
// src/dst fe80::1 / fe80::2
|
|
||||||
pkt[8] = 0xfe
|
|
||||||
pkt[9] = 0x80
|
|
||||||
pkt[23] = 1
|
|
||||||
pkt[24] = 0xfe
|
|
||||||
pkt[25] = 0x80
|
|
||||||
pkt[39] = 2
|
|
||||||
|
|
||||||
// TCP header
|
|
||||||
binary.BigEndian.PutUint16(pkt[40:42], 12345)
|
|
||||||
binary.BigEndian.PutUint16(pkt[42:44], 80)
|
|
||||||
binary.BigEndian.PutUint32(pkt[44:48], 7)
|
|
||||||
binary.BigEndian.PutUint32(pkt[48:52], 99)
|
|
||||||
pkt[52] = 0x50
|
|
||||||
pkt[53] = 0x19 // FIN | ACK | PSH — exercise FIN clearing too
|
|
||||||
binary.BigEndian.PutUint16(pkt[54:56], 65535)
|
|
||||||
|
|
||||||
for i := 0; i < payLen; i++ {
|
|
||||||
pkt[ipLen+tcpLen+i] = byte(i)
|
|
||||||
}
|
|
||||||
|
|
||||||
hdr := virtio.Hdr{
|
|
||||||
Flags: unix.VIRTIO_NET_HDR_F_NEEDS_CSUM,
|
|
||||||
GSOType: unix.VIRTIO_NET_HDR_GSO_TCPV6,
|
|
||||||
HdrLen: uint16(ipLen + tcpLen),
|
|
||||||
GSOSize: uint16(mss),
|
|
||||||
CsumStart: uint16(ipLen),
|
|
||||||
CsumOffset: 16,
|
|
||||||
}
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != numSeg {
|
|
||||||
t.Fatalf("want %d segments, got %d", numSeg, len(out))
|
|
||||||
}
|
|
||||||
|
|
||||||
for i, seg := range out {
|
|
||||||
if len(seg) != ipLen+tcpLen+mss {
|
|
||||||
t.Errorf("seg %d: len %d want %d", i, len(seg), ipLen+tcpLen+mss)
|
|
||||||
}
|
|
||||||
pl := binary.BigEndian.Uint16(seg[4:6])
|
|
||||||
if pl != uint16(tcpLen+mss) {
|
|
||||||
t.Errorf("seg %d: payload_length=%d want %d", i, pl, tcpLen+mss)
|
|
||||||
}
|
|
||||||
seq := binary.BigEndian.Uint32(seg[44:48])
|
|
||||||
if seq != uint32(7+i*mss) {
|
|
||||||
t.Errorf("seg %d: seq=%d want %d", i, seq, 7+i*mss)
|
|
||||||
}
|
|
||||||
flags := seg[53]
|
|
||||||
// Original flags = 0x19 (FIN|ACK|PSH). FIN(0x01)+PSH(0x08) should be
|
|
||||||
// cleared on all but the last; ACK(0x10) always preserved.
|
|
||||||
wantFlags := byte(0x10)
|
|
||||||
if i == numSeg-1 {
|
|
||||||
wantFlags = 0x19
|
|
||||||
}
|
|
||||||
if flags != wantFlags {
|
|
||||||
t.Errorf("seg %d: flags=%#x want %#x", i, flags, wantFlags)
|
|
||||||
}
|
|
||||||
psum := pseudoHeaderIPv6(seg[8:24], seg[24:40], unix.IPPROTO_TCP, tcpLen+mss)
|
|
||||||
if !verifyChecksum(seg[ipLen:], psum) {
|
|
||||||
t.Errorf("seg %d: bad TCP checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSegmentGSONonePassesThrough(t *testing.T) {
|
|
||||||
pkt, hdr := buildTSOv4(t, 100, 100)
|
|
||||||
hdr.GSOType = unix.VIRTIO_NET_HDR_GSO_NONE
|
|
||||||
hdr.Flags = 0 // no NEEDS_CSUM, leave packet untouched
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != 1 {
|
|
||||||
t.Fatalf("want 1 segment, got %d", len(out))
|
|
||||||
}
|
|
||||||
if len(out[0]) != len(pkt) {
|
|
||||||
t.Fatalf("unexpected length: %d vs %d", len(out[0]), len(pkt))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSegmentRejectsLegacyUDPGSO ensures the legacy GSO_UDP (UFO) marker is
|
|
||||||
// still rejected; only modern GSO_UDP_L4 (USO) is supported.
|
|
||||||
func TestSegmentRejectsLegacyUDPGSO(t *testing.T) {
|
|
||||||
hdr := virtio.Hdr{GSOType: unix.VIRTIO_NET_HDR_GSO_UDP}
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(nil, hdr, &out, nil); err == nil {
|
|
||||||
t.Fatalf("expected rejection for legacy UDP GSO")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildUSOv4 builds a synthetic IPv4/UDP USO superpacket with payload of
|
|
||||||
// payLen bytes, segmented at gsoSize.
|
|
||||||
func buildUSOv4(t *testing.T, payLen, gsoSize int) ([]byte, virtio.Hdr) {
|
|
||||||
t.Helper()
|
|
||||||
const ipLen = 20
|
|
||||||
const udpLen = 8
|
|
||||||
pkt := make([]byte, ipLen+udpLen+payLen)
|
|
||||||
|
|
||||||
// IPv4 header
|
|
||||||
pkt[0] = 0x45 // version 4, IHL 5
|
|
||||||
binary.BigEndian.PutUint16(pkt[2:4], uint16(ipLen+udpLen+payLen))
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], 0x4242)
|
|
||||||
pkt[8] = 64
|
|
||||||
pkt[9] = unix.IPPROTO_UDP
|
|
||||||
copy(pkt[12:16], []byte{10, 0, 0, 1})
|
|
||||||
copy(pkt[16:20], []byte{10, 0, 0, 2})
|
|
||||||
|
|
||||||
// UDP header (length + checksum filled in per segment by segmentUDPYield)
|
|
||||||
binary.BigEndian.PutUint16(pkt[20:22], 12345) // sport
|
|
||||||
binary.BigEndian.PutUint16(pkt[22:24], 53) // dport
|
|
||||||
|
|
||||||
for i := 0; i < payLen; i++ {
|
|
||||||
pkt[ipLen+udpLen+i] = byte(i & 0xff)
|
|
||||||
}
|
|
||||||
|
|
||||||
return pkt, virtio.Hdr{
|
|
||||||
Flags: unix.VIRTIO_NET_HDR_F_NEEDS_CSUM,
|
|
||||||
GSOType: unix.VIRTIO_NET_HDR_GSO_UDP_L4,
|
|
||||||
HdrLen: uint16(ipLen + udpLen),
|
|
||||||
GSOSize: uint16(gsoSize),
|
|
||||||
CsumStart: uint16(ipLen),
|
|
||||||
CsumOffset: 6,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSegmentUDPv4(t *testing.T) {
|
|
||||||
const gso = 100
|
|
||||||
const numSeg = 3
|
|
||||||
pkt, hdr := buildUSOv4(t, gso*numSeg, gso)
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != numSeg {
|
|
||||||
t.Fatalf("expected %d segments, got %d", numSeg, len(out))
|
|
||||||
}
|
|
||||||
|
|
||||||
for i, seg := range out {
|
|
||||||
if len(seg) != 28+gso {
|
|
||||||
t.Errorf("seg %d: len %d want %d", i, len(seg), 28+gso)
|
|
||||||
}
|
|
||||||
totalLen := binary.BigEndian.Uint16(seg[2:4])
|
|
||||||
if totalLen != uint16(28+gso) {
|
|
||||||
t.Errorf("seg %d: total_len=%d want %d", i, totalLen, 28+gso)
|
|
||||||
}
|
|
||||||
// kernel UDP-GSO does NOT bump the IPv4 ID across segments; every
|
|
||||||
// segment carries the same ID as the seed.
|
|
||||||
id := binary.BigEndian.Uint16(seg[4:6])
|
|
||||||
if id != 0x4242 {
|
|
||||||
t.Errorf("seg %d: ip id=%#x want %#x", i, id, 0x4242)
|
|
||||||
}
|
|
||||||
udpLen := binary.BigEndian.Uint16(seg[24:26])
|
|
||||||
if udpLen != uint16(8+gso) {
|
|
||||||
t.Errorf("seg %d: udp len=%d want %d", i, udpLen, 8+gso)
|
|
||||||
}
|
|
||||||
if !verifyChecksum(seg[:20], 0) {
|
|
||||||
t.Errorf("seg %d: bad IPv4 header checksum", i)
|
|
||||||
}
|
|
||||||
psum := pseudoHeaderIPv4(seg[12:16], seg[16:20], unix.IPPROTO_UDP, 8+gso)
|
|
||||||
if !verifyChecksum(seg[20:], psum) {
|
|
||||||
t.Errorf("seg %d: bad UDP checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSegmentUDPv4OddTail(t *testing.T) {
|
|
||||||
// 250 bytes payload, gsoSize=100 → segments of 100, 100, 50.
|
|
||||||
pkt, hdr := buildUSOv4(t, 250, 100)
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != 3 {
|
|
||||||
t.Fatalf("want 3 segments, got %d", len(out))
|
|
||||||
}
|
|
||||||
wantPay := []int{100, 100, 50}
|
|
||||||
for i, seg := range out {
|
|
||||||
if len(seg)-28 != wantPay[i] {
|
|
||||||
t.Errorf("seg %d: pay len %d want %d", i, len(seg)-28, wantPay[i])
|
|
||||||
}
|
|
||||||
udpLen := binary.BigEndian.Uint16(seg[24:26])
|
|
||||||
if udpLen != uint16(8+wantPay[i]) {
|
|
||||||
t.Errorf("seg %d: udp len=%d want %d", i, udpLen, 8+wantPay[i])
|
|
||||||
}
|
|
||||||
if !verifyChecksum(seg[:20], 0) {
|
|
||||||
t.Errorf("seg %d: bad IPv4 header checksum", i)
|
|
||||||
}
|
|
||||||
psum := pseudoHeaderIPv4(seg[12:16], seg[16:20], unix.IPPROTO_UDP, 8+wantPay[i])
|
|
||||||
if !verifyChecksum(seg[20:], psum) {
|
|
||||||
t.Errorf("seg %d: bad UDP checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSegmentUDPv6(t *testing.T) {
|
|
||||||
const ipLen = 40
|
|
||||||
const udpLen = 8
|
|
||||||
const gso = 120
|
|
||||||
const numSeg = 2
|
|
||||||
payLen := gso * numSeg
|
|
||||||
pkt := make([]byte, ipLen+udpLen+payLen)
|
|
||||||
|
|
||||||
// IPv6 header
|
|
||||||
pkt[0] = 0x60
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], uint16(udpLen+payLen))
|
|
||||||
pkt[6] = unix.IPPROTO_UDP
|
|
||||||
pkt[7] = 64
|
|
||||||
pkt[8] = 0xfe
|
|
||||||
pkt[9] = 0x80
|
|
||||||
pkt[23] = 1
|
|
||||||
pkt[24] = 0xfe
|
|
||||||
pkt[25] = 0x80
|
|
||||||
pkt[39] = 2
|
|
||||||
|
|
||||||
binary.BigEndian.PutUint16(pkt[40:42], 12345)
|
|
||||||
binary.BigEndian.PutUint16(pkt[42:44], 53)
|
|
||||||
|
|
||||||
for i := 0; i < payLen; i++ {
|
|
||||||
pkt[ipLen+udpLen+i] = byte(i)
|
|
||||||
}
|
|
||||||
|
|
||||||
hdr := virtio.Hdr{
|
|
||||||
Flags: unix.VIRTIO_NET_HDR_F_NEEDS_CSUM,
|
|
||||||
GSOType: unix.VIRTIO_NET_HDR_GSO_UDP_L4,
|
|
||||||
HdrLen: uint16(ipLen + udpLen),
|
|
||||||
GSOSize: uint16(gso),
|
|
||||||
CsumStart: uint16(ipLen),
|
|
||||||
CsumOffset: 6,
|
|
||||||
}
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != numSeg {
|
|
||||||
t.Fatalf("want %d segments, got %d", numSeg, len(out))
|
|
||||||
}
|
|
||||||
|
|
||||||
for i, seg := range out {
|
|
||||||
if len(seg) != ipLen+udpLen+gso {
|
|
||||||
t.Errorf("seg %d: len %d want %d", i, len(seg), ipLen+udpLen+gso)
|
|
||||||
}
|
|
||||||
pl := binary.BigEndian.Uint16(seg[4:6])
|
|
||||||
if pl != uint16(udpLen+gso) {
|
|
||||||
t.Errorf("seg %d: payload_length=%d want %d", i, pl, udpLen+gso)
|
|
||||||
}
|
|
||||||
ul := binary.BigEndian.Uint16(seg[ipLen+4 : ipLen+6])
|
|
||||||
if ul != uint16(udpLen+gso) {
|
|
||||||
t.Errorf("seg %d: udp len=%d want %d", i, ul, udpLen+gso)
|
|
||||||
}
|
|
||||||
psum := pseudoHeaderIPv6(seg[8:24], seg[24:40], unix.IPPROTO_UDP, udpLen+gso)
|
|
||||||
if !verifyChecksum(seg[ipLen:], psum) {
|
|
||||||
t.Errorf("seg %d: bad UDP checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSegmentUDPCEPropagates confirms IP-level CE marks on the seed appear on
|
|
||||||
// every segment. UDP has no transport-level CWR/ECE: the IP TOS/TC byte is
|
|
||||||
// copied verbatim into every segment by the segment-prefix copy.
|
|
||||||
func TestSegmentUDPCEPropagates(t *testing.T) {
|
|
||||||
pkt, hdr := buildUSOv4(t, 200, 100)
|
|
||||||
pkt[1] = 0x03 // CE codepoint in IP-ECN
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != 2 {
|
|
||||||
t.Fatalf("want 2 segments, got %d", len(out))
|
|
||||||
}
|
|
||||||
for i, seg := range out {
|
|
||||||
if seg[1]&0x03 != 0x03 {
|
|
||||||
t.Errorf("seg %d: CE missing (tos=%#x)", i, seg[1])
|
|
||||||
}
|
|
||||||
if !verifyChecksum(seg[:20], 0) {
|
|
||||||
t.Errorf("seg %d: bad IPv4 header checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSegmentTCPCwrFirstSegmentOnly confirms RFC 3168 §6.1.2: when a TSO
|
|
||||||
// burst's seed has CWR set, only the first emitted segment carries CWR.
|
|
||||||
// ECE is preserved on every segment (different signal, persistent state).
|
|
||||||
func TestSegmentTCPCwrFirstSegmentOnly(t *testing.T) {
|
|
||||||
const mss = 100
|
|
||||||
const numSeg = 3
|
|
||||||
pkt, hdr := buildTSOv4(t, mss*numSeg, mss)
|
|
||||||
// Seed flags: CWR | ECE | ACK | PSH.
|
|
||||||
pkt[33] = 0x80 | 0x40 | 0x10 | 0x08
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
var out [][]byte
|
|
||||||
if err := segmentForTest(pkt, hdr, &out, scratch); err != nil {
|
|
||||||
t.Fatalf("segmentForTest: %v", err)
|
|
||||||
}
|
|
||||||
if len(out) != numSeg {
|
|
||||||
t.Fatalf("expected %d segments, got %d", numSeg, len(out))
|
|
||||||
}
|
|
||||||
for i, seg := range out {
|
|
||||||
flags := seg[33]
|
|
||||||
hasCwr := flags&0x80 != 0
|
|
||||||
hasEce := flags&0x40 != 0
|
|
||||||
hasPsh := flags&0x08 != 0
|
|
||||||
wantCwr := i == 0
|
|
||||||
wantPsh := i == numSeg-1
|
|
||||||
if hasCwr != wantCwr {
|
|
||||||
t.Errorf("seg %d: CWR=%v want %v (flags=%#x)", i, hasCwr, wantCwr, flags)
|
|
||||||
}
|
|
||||||
if !hasEce {
|
|
||||||
t.Errorf("seg %d: ECE missing (flags=%#x)", i, flags)
|
|
||||||
}
|
|
||||||
if hasPsh != wantPsh {
|
|
||||||
t.Errorf("seg %d: PSH=%v want %v (flags=%#x)", i, hasPsh, wantPsh, flags)
|
|
||||||
}
|
|
||||||
// IP and TCP checksums must still verify after the flag rewrite.
|
|
||||||
if !verifyChecksum(seg[:20], 0) {
|
|
||||||
t.Errorf("seg %d: bad IPv4 header checksum", i)
|
|
||||||
}
|
|
||||||
psum := pseudoHeaderIPv4(seg[12:16], seg[16:20], unix.IPPROTO_TCP, 20+mss)
|
|
||||||
if !verifyChecksum(seg[20:], psum) {
|
|
||||||
t.Errorf("seg %d: bad TCP checksum", i)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func BenchmarkSegmentTCPv4(b *testing.B) {
|
|
||||||
sizes := []struct {
|
|
||||||
name string
|
|
||||||
payLen int
|
|
||||||
mss int
|
|
||||||
}{
|
|
||||||
{"64KiB_MSS1460", 65000, 1460},
|
|
||||||
{"16KiB_MSS1460", 16384, 1460},
|
|
||||||
{"4KiB_MSS1460", 4096, 1460},
|
|
||||||
}
|
|
||||||
for _, sz := range sizes {
|
|
||||||
b.Run(sz.name, func(b *testing.B) {
|
|
||||||
const ipLen = 20
|
|
||||||
const tcpLen = 20
|
|
||||||
pkt := make([]byte, ipLen+tcpLen+sz.payLen)
|
|
||||||
pkt[0] = 0x45
|
|
||||||
binary.BigEndian.PutUint16(pkt[2:4], uint16(ipLen+tcpLen+sz.payLen))
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], 0x4242)
|
|
||||||
pkt[8] = 64
|
|
||||||
pkt[9] = unix.IPPROTO_TCP
|
|
||||||
copy(pkt[12:16], []byte{10, 0, 0, 1})
|
|
||||||
copy(pkt[16:20], []byte{10, 0, 0, 2})
|
|
||||||
binary.BigEndian.PutUint16(pkt[20:22], 12345)
|
|
||||||
binary.BigEndian.PutUint16(pkt[22:24], 80)
|
|
||||||
binary.BigEndian.PutUint32(pkt[24:28], 10000)
|
|
||||||
binary.BigEndian.PutUint32(pkt[28:32], 20000)
|
|
||||||
pkt[32] = 0x50
|
|
||||||
pkt[33] = 0x18
|
|
||||||
binary.BigEndian.PutUint16(pkt[34:36], 65535)
|
|
||||||
for i := 0; i < sz.payLen; i++ {
|
|
||||||
pkt[ipLen+tcpLen+i] = byte(i)
|
|
||||||
}
|
|
||||||
hdr := virtio.Hdr{
|
|
||||||
Flags: unix.VIRTIO_NET_HDR_F_NEEDS_CSUM,
|
|
||||||
GSOType: unix.VIRTIO_NET_HDR_GSO_TCPV4,
|
|
||||||
HdrLen: uint16(ipLen + tcpLen),
|
|
||||||
GSOSize: uint16(sz.mss),
|
|
||||||
CsumStart: uint16(ipLen),
|
|
||||||
CsumOffset: 16,
|
|
||||||
}
|
|
||||||
|
|
||||||
scratch := make([]byte, testSegScratchSize)
|
|
||||||
out := make([][]byte, 0, 64)
|
|
||||||
|
|
||||||
// PerSegment consumes its input destructively; restore pkt from
|
|
||||||
// a master copy each iteration. The restore mirrors the
|
|
||||||
// kernel→userspace copy that hands a fresh GSO blob to the
|
|
||||||
// segmenter in production, so it's representative cost rather
|
|
||||||
// than bench overhead.
|
|
||||||
master := append([]byte(nil), pkt...)
|
|
||||||
work := make([]byte, len(pkt))
|
|
||||||
|
|
||||||
b.SetBytes(int64(len(pkt)))
|
|
||||||
b.ResetTimer()
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
copy(work, master)
|
|
||||||
out = out[:0]
|
|
||||||
if err := segmentForTest(work, hdr, &out, scratch); err != nil {
|
|
||||||
b.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestTunFileWriteVnetHdrNoAlloc verifies the IFF_VNET_HDR fast-path write is
|
|
||||||
// allocation-free. We write to /dev/null so every call succeeds synchronously.
|
|
||||||
func TestTunFileWriteVnetHdrNoAlloc(t *testing.T) {
|
|
||||||
fd, err := unix.Open("/dev/null", os.O_WRONLY, 0)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("open /dev/null: %v", err)
|
|
||||||
}
|
|
||||||
t.Cleanup(func() { _ = unix.Close(fd) })
|
|
||||||
|
|
||||||
tf := &Offload{fd: fd}
|
|
||||||
|
|
||||||
payload := make([]byte, 1400)
|
|
||||||
// Warm up (first call may trigger one-time internal allocations elsewhere).
|
|
||||||
if _, err := tf.Write(payload); err != nil {
|
|
||||||
t.Fatalf("Write: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
allocs := testing.AllocsPerRun(1000, func() {
|
|
||||||
if _, err := tf.Write(payload); err != nil {
|
|
||||||
t.Fatalf("Write: %v", err)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
if allocs != 0 {
|
|
||||||
t.Fatalf("Write allocated %.1f times per call, want 0", allocs)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildTSOv6 builds a synthetic IPv6/TCP TSO superpacket with payLen bytes
|
|
||||||
// of payload, segmented at gso. Returns the packet bytes only; the
|
|
||||||
// virtio_net_hdr is the caller's responsibility.
|
|
||||||
func buildTSOv6(payLen, gso int) []byte {
|
|
||||||
const ipLen = 40
|
|
||||||
const tcpLen = 20
|
|
||||||
pkt := make([]byte, ipLen+tcpLen+payLen)
|
|
||||||
|
|
||||||
pkt[0] = 0x60 // version 6
|
|
||||||
binary.BigEndian.PutUint16(pkt[4:6], uint16(tcpLen+payLen))
|
|
||||||
pkt[6] = unix.IPPROTO_TCP
|
|
||||||
pkt[7] = 64
|
|
||||||
pkt[8] = 0xfe
|
|
||||||
pkt[9] = 0x80
|
|
||||||
pkt[23] = 1
|
|
||||||
pkt[24] = 0xfe
|
|
||||||
pkt[25] = 0x80
|
|
||||||
pkt[39] = 2
|
|
||||||
|
|
||||||
binary.BigEndian.PutUint16(pkt[40:42], 12345)
|
|
||||||
binary.BigEndian.PutUint16(pkt[42:44], 80)
|
|
||||||
binary.BigEndian.PutUint32(pkt[44:48], 7)
|
|
||||||
binary.BigEndian.PutUint32(pkt[48:52], 99)
|
|
||||||
pkt[52] = 0x50
|
|
||||||
pkt[53] = 0x10 // ACK only
|
|
||||||
binary.BigEndian.PutUint16(pkt[54:56], 65535)
|
|
||||||
|
|
||||||
for i := 0; i < payLen; i++ {
|
|
||||||
pkt[ipLen+tcpLen+i] = byte(i)
|
|
||||||
}
|
|
||||||
return pkt
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestDecodeReadFitsMaxTSO proves decodeRead can absorb a worst-case
|
|
||||||
// 64KiB TSO superpacket without dropping it. With segmentation deferred to
|
|
||||||
// encrypt time, decodeRead writes nothing — it just slices the
|
|
||||||
// caller-supplied mem and attaches GSO metadata — so the size requirement
|
|
||||||
// is just "fit one worst-case input."
|
|
||||||
//
|
|
||||||
// Regression history: in a prior layout the rx buffer doubled as the
|
|
||||||
// segmentation output, a near-threshold drain read returned "scratch too
|
|
||||||
// small", the whole 45-segment TSO burst was dropped, and the remote's TCP
|
|
||||||
// fast-retransmit collapsed cwnd. Keeping this test guards against
|
|
||||||
// re-introducing per-call sizing assumptions inside decodeRead.
|
|
||||||
func TestDecodeReadFitsMaxTSO(t *testing.T) {
|
|
||||||
const ipv6HdrLen = 40
|
|
||||||
const tcpHdrLen = 20
|
|
||||||
const headerLen = ipv6HdrLen + tcpHdrLen
|
|
||||||
pktLen := tunReadBufSize
|
|
||||||
payLen := pktLen - headerLen
|
|
||||||
const targetSegs = 64
|
|
||||||
gsoSize := (payLen + targetSegs - 1) / targetSegs
|
|
||||||
|
|
||||||
pkt := buildTSOv6(payLen, gsoSize)
|
|
||||||
if len(pkt) != pktLen {
|
|
||||||
t.Fatalf("buildTSOv6 produced %d bytes, want %d", len(pkt), pktLen)
|
|
||||||
}
|
|
||||||
|
|
||||||
o := &Offload{}
|
|
||||||
// mem is sized exactly to one worst-case packet — the caller-side
|
|
||||||
// invariant the drain loop in Read enforces. decodeRead must process
|
|
||||||
// the burst within that window.
|
|
||||||
mem := make([]byte, pktLen)
|
|
||||||
copy(mem, pkt)
|
|
||||||
|
|
||||||
// Encode the matching virtio_net_hdr.
|
|
||||||
hdr := virtio.Hdr{
|
|
||||||
Flags: unix.VIRTIO_NET_HDR_F_NEEDS_CSUM,
|
|
||||||
GSOType: unix.VIRTIO_NET_HDR_GSO_TCPV6,
|
|
||||||
HdrLen: uint16(headerLen),
|
|
||||||
GSOSize: uint16(gsoSize),
|
|
||||||
CsumStart: uint16(ipv6HdrLen),
|
|
||||||
CsumOffset: 16,
|
|
||||||
}
|
|
||||||
hdr.Encode(o.readVnetScratch[:])
|
|
||||||
|
|
||||||
var pkts []wire.TunPacket
|
|
||||||
pkts, err := o.decodeRead(pkts, mem, pktLen)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("decodeRead returned %v — sizing regression: "+
|
|
||||||
"tunRxBufSize=%d must hold one worst-case input (%d)",
|
|
||||||
err, tunRxBufSize, pktLen)
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(pkts) != 1 {
|
|
||||||
t.Fatalf("got %d packets, want 1 superpacket entry", len(pkts))
|
|
||||||
}
|
|
||||||
got := pkts[0]
|
|
||||||
if !got.Meta.IsSuperpacket() {
|
|
||||||
t.Fatalf("expected superpacket GSO metadata, got %+v", got.Meta)
|
|
||||||
}
|
|
||||||
if got.Meta.Proto != wire.GSOProtoTCP {
|
|
||||||
t.Errorf("Meta.Proto=%d want TCP", got.Meta.Proto)
|
|
||||||
}
|
|
||||||
if got.Meta.Size != uint16(gsoSize) {
|
|
||||||
t.Errorf("Meta.Size=%d want %d", got.Meta.Size, gsoSize)
|
|
||||||
}
|
|
||||||
if got.Meta.HdrLen != uint16(headerLen) {
|
|
||||||
t.Errorf("Meta.HdrLen=%d want %d", got.Meta.HdrLen, headerLen)
|
|
||||||
}
|
|
||||||
if got.Meta.CsumStart != uint16(ipv6HdrLen) {
|
|
||||||
t.Errorf("Meta.CsumStart=%d want %d", got.Meta.CsumStart, ipv6HdrLen)
|
|
||||||
}
|
|
||||||
if len(got.Bytes) != pktLen {
|
|
||||||
t.Errorf("len(Bytes)=%d want %d", len(got.Bytes), pktLen)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Validate that segmenting the returned superpacket reproduces the
|
|
||||||
// expected per-segment IPv6 payload length and TCP checksum.
|
|
||||||
wantSegs := (payLen + gsoSize - 1) / gsoSize
|
|
||||||
gotSegs := 0
|
|
||||||
if err := got.PerSegment(func(seg []byte) error {
|
|
||||||
defer func() { gotSegs++ }()
|
|
||||||
if len(seg) < headerLen+1 {
|
|
||||||
t.Errorf("seg %d too short: %d", gotSegs, len(seg))
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
if seg[0]>>4 != 6 {
|
|
||||||
t.Errorf("seg %d: bad IP version %#x", gotSegs, seg[0])
|
|
||||||
}
|
|
||||||
segPay := len(seg) - headerLen
|
|
||||||
gotPL := binary.BigEndian.Uint16(seg[4:6])
|
|
||||||
if gotPL != uint16(tcpHdrLen+segPay) {
|
|
||||||
t.Errorf("seg %d: payload_len=%d want %d", gotSegs, gotPL, tcpHdrLen+segPay)
|
|
||||||
}
|
|
||||||
psum := pseudoHeaderIPv6(seg[8:24], seg[24:40], unix.IPPROTO_TCP, tcpHdrLen+segPay)
|
|
||||||
if !verifyChecksum(seg[ipv6HdrLen:], psum) {
|
|
||||||
t.Errorf("seg %d: bad TCP checksum", gotSegs)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}); err != nil {
|
|
||||||
t.Fatalf("PerSegment: %v", err)
|
|
||||||
}
|
|
||||||
if gotSegs != wantSegs {
|
|
||||||
t.Fatalf("got %d segments, want %d", gotSegs, wantSegs)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
//go:build linux && !android
|
|
||||||
// +build linux,!android
|
|
||||||
|
|
||||||
package virtio
|
|
||||||
|
|
||||||
import "encoding/binary"
|
|
||||||
|
|
||||||
// Size is the on-wire length of struct virtio_net_hdr the kernel
|
|
||||||
// prepends/expects on a TUN opened with IFF_VNET_HDR (TUNSETVNETHDRSZ
|
|
||||||
// not set).
|
|
||||||
const Size = 10
|
|
||||||
|
|
||||||
// Hdr is the Go view of the legacy virtio_net_hdr.
|
|
||||||
type Hdr struct {
|
|
||||||
Flags uint8
|
|
||||||
GSOType uint8
|
|
||||||
HdrLen uint16
|
|
||||||
GSOSize uint16
|
|
||||||
CsumStart uint16
|
|
||||||
CsumOffset uint16
|
|
||||||
}
|
|
||||||
|
|
||||||
// Decode reads a virtio_net_hdr in host byte order (TUN default; we never
|
|
||||||
// call TUNSETVNETLE so the kernel matches our endianness).
|
|
||||||
func (h *Hdr) Decode(b []byte) {
|
|
||||||
h.Flags = b[0]
|
|
||||||
h.GSOType = b[1]
|
|
||||||
h.HdrLen = binary.NativeEndian.Uint16(b[2:4])
|
|
||||||
h.GSOSize = binary.NativeEndian.Uint16(b[4:6])
|
|
||||||
h.CsumStart = binary.NativeEndian.Uint16(b[6:8])
|
|
||||||
h.CsumOffset = binary.NativeEndian.Uint16(b[8:10])
|
|
||||||
}
|
|
||||||
|
|
||||||
// Encode is the inverse of Decode: writes the virtio_net_hdr fields into b
|
|
||||||
// (must be at least Size bytes). Used to emit a TSO superpacket on egress.
|
|
||||||
func (h *Hdr) Encode(b []byte) {
|
|
||||||
b[0] = h.Flags
|
|
||||||
b[1] = h.GSOType
|
|
||||||
binary.NativeEndian.PutUint16(b[2:4], h.HdrLen)
|
|
||||||
binary.NativeEndian.PutUint16(b[4:6], h.GSOSize)
|
|
||||||
binary.NativeEndian.PutUint16(b[6:8], h.CsumStart)
|
|
||||||
binary.NativeEndian.PutUint16(b[8:10], h.CsumOffset)
|
|
||||||
}
|
|
||||||
@@ -1,402 +0,0 @@
|
|||||||
//go:build linux && !android
|
|
||||||
// +build linux,!android
|
|
||||||
|
|
||||||
// Package virtio implements the pure validation, header-correction, and
|
|
||||||
// per-segment slicing logic for kernel-supplied TSO/USO superpackets on
|
|
||||||
// IFF_VNET_HDR TUN devices. It is FD-free and depends only on the byte
|
|
||||||
// layout of the virtio_net_hdr and the IP/TCP/UDP headers it describes,
|
|
||||||
// so it can be unit-tested in isolation from the tio Queue runtime.
|
|
||||||
package virtio
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/overlay/checksum"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Protocol header size bounds used to validate / cap kernel-supplied offsets.
|
|
||||||
const (
|
|
||||||
ipv4HeaderMinLen = 20 // IHL=5, no options
|
|
||||||
ipv4HeaderMaxLen = 60 // IHL=15, max options
|
|
||||||
ipv6FixedLen = 40 // IPv6 base header; extensions would extend this
|
|
||||||
tcpHeaderMinLen = 20 // data-offset=5, no options
|
|
||||||
tcpHeaderMaxLen = 60 // data-offset=15, max options
|
|
||||||
)
|
|
||||||
|
|
||||||
// Byte offsets inside an IPv4 header.
|
|
||||||
const (
|
|
||||||
ipv4TotalLenOff = 2
|
|
||||||
ipv4IDOff = 4
|
|
||||||
ipv4ChecksumOff = 10
|
|
||||||
ipv4SrcOff = 12
|
|
||||||
ipv4AddrsEnd = 20 // end of dst address (ipv4SrcOff + 2*4)
|
|
||||||
)
|
|
||||||
|
|
||||||
// Byte offsets inside an IPv6 header.
|
|
||||||
const (
|
|
||||||
ipv6PayloadLenOff = 4
|
|
||||||
ipv6SrcOff = 8
|
|
||||||
ipv6AddrsEnd = 40 // end of dst address (ipv6SrcOff + 2*16)
|
|
||||||
)
|
|
||||||
|
|
||||||
// Byte offsets inside a TCP header (relative to its start, i.e. csumStart).
|
|
||||||
const (
|
|
||||||
tcpSeqOff = 4
|
|
||||||
tcpDataOffOff = 12 // upper nibble is header len in 32-bit words
|
|
||||||
tcpFlagsOff = 13
|
|
||||||
tcpChecksumOff = 16
|
|
||||||
)
|
|
||||||
|
|
||||||
// UDP header is fixed at 8 bytes: {sport, dport, length, checksum}.
|
|
||||||
const (
|
|
||||||
udpHeaderLen = 8
|
|
||||||
udpLengthOff = 4
|
|
||||||
udpChecksumOff = 6
|
|
||||||
)
|
|
||||||
|
|
||||||
// tcpFinPshMask is cleared on every segment except the last of a TSO burst.
|
|
||||||
const tcpFinPshMask = 0x09 // FIN(0x01) | PSH(0x08)
|
|
||||||
|
|
||||||
// tcpCwrFlag is cleared on every segment except the first. Per RFC 3168
|
|
||||||
// §6.1.2 the CWR bit signals a one-shot transition (the sender just halved
|
|
||||||
// its window) and must appear on the first segment of a TSO burst only.
|
|
||||||
const tcpCwrFlag = 0x80
|
|
||||||
|
|
||||||
// CheckValid rejects packets whose virtio_net_hdr/IP combination would
|
|
||||||
// cause a downstream miscompute. The TUN should never emit RSC_INFO and
|
|
||||||
// the GSO type must agree with the IP version nibble.
|
|
||||||
func CheckValid(pkt []byte, hdr Hdr) error {
|
|
||||||
// When RSC_INFO is set the csum_start/csum_offset fields are repurposed to
|
|
||||||
// carry coalescing info rather than checksum offsets. A TUN writing via
|
|
||||||
// IFF_VNET_HDR should never emit this, but if it did we would silently
|
|
||||||
// miscompute the segment checksums — refuse the packet instead.
|
|
||||||
if hdr.Flags&unix.VIRTIO_NET_HDR_F_RSC_INFO != 0 {
|
|
||||||
return fmt.Errorf("virtio RSC_INFO flag not supported on TUN reads")
|
|
||||||
}
|
|
||||||
if len(pkt) < ipv4HeaderMinLen {
|
|
||||||
return fmt.Errorf("packet too short")
|
|
||||||
}
|
|
||||||
ipVersion := pkt[0] >> 4
|
|
||||||
switch hdr.GSOType {
|
|
||||||
case unix.VIRTIO_NET_HDR_GSO_TCPV4:
|
|
||||||
if ipVersion != 4 {
|
|
||||||
return fmt.Errorf("invalid IP version %d for GSO type %d", ipVersion, hdr.GSOType)
|
|
||||||
}
|
|
||||||
case unix.VIRTIO_NET_HDR_GSO_TCPV6:
|
|
||||||
if ipVersion != 6 {
|
|
||||||
return fmt.Errorf("invalid IP version %d for GSO type %d", ipVersion, hdr.GSOType)
|
|
||||||
}
|
|
||||||
case unix.VIRTIO_NET_HDR_GSO_UDP_L4:
|
|
||||||
// USO carries either v4 or v6; the leading nibble disambiguates.
|
|
||||||
if !(ipVersion == 4 || ipVersion == 6) {
|
|
||||||
return fmt.Errorf("invalid IP version %d for GSO type %d", ipVersion, hdr.GSOType)
|
|
||||||
}
|
|
||||||
default:
|
|
||||||
if !(ipVersion == 6 || ipVersion == 4) {
|
|
||||||
return fmt.Errorf("invalid IP version %d for GSO type %d", ipVersion, hdr.GSOType)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// CorrectHdrLen rewrites hdr.HdrLen based on the actual transport header
|
|
||||||
// length read out of pkt. The kernel's hdr.HdrLen on the FORWARD path can
|
|
||||||
// be the length of the entire first packet, so we don't trust it.
|
|
||||||
func CorrectHdrLen(pkt []byte, hdr *Hdr) error {
|
|
||||||
// Thank you wireguard-go for documenting these edge-cases
|
|
||||||
// Don't trust hdr.hdrLen from the kernel as it can be equal to the length
|
|
||||||
// of the entire first packet when the kernel is handling it as part of a
|
|
||||||
// FORWARD path. Instead, parse the transport header length and add it onto
|
|
||||||
// csumStart, which is synonymous for IP header length.
|
|
||||||
|
|
||||||
if hdr.GSOType == unix.VIRTIO_NET_HDR_GSO_UDP_L4 {
|
|
||||||
hdr.HdrLen = hdr.CsumStart + 8
|
|
||||||
} else {
|
|
||||||
if len(pkt) <= int(hdr.CsumStart+tcpDataOffOff) {
|
|
||||||
return errors.New("packet is too short")
|
|
||||||
}
|
|
||||||
|
|
||||||
tcpHLen := uint16(pkt[hdr.CsumStart+tcpDataOffOff] >> 4 * 4)
|
|
||||||
if tcpHLen < 20 || tcpHLen > 60 {
|
|
||||||
// A TCP header must be between 20 and 60 bytes in length.
|
|
||||||
return fmt.Errorf("tcp header len is invalid: %d", tcpHLen)
|
|
||||||
}
|
|
||||||
hdr.HdrLen = hdr.CsumStart + tcpHLen
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(pkt) < int(hdr.HdrLen) {
|
|
||||||
return fmt.Errorf("length of packet (%d) < virtioNetHdr.HdrLen (%d)", len(pkt), hdr.HdrLen)
|
|
||||||
}
|
|
||||||
|
|
||||||
if hdr.HdrLen < hdr.CsumStart {
|
|
||||||
return fmt.Errorf("virtioNetHdr.HdrLen (%d) < virtioNetHdr.CsumStart (%d)", hdr.HdrLen, hdr.CsumStart)
|
|
||||||
}
|
|
||||||
cSumAt := int(hdr.CsumStart + hdr.CsumStart)
|
|
||||||
if cSumAt+1 >= len(pkt) {
|
|
||||||
return fmt.Errorf("end of checksum offset (%d) exceeds packet length (%d)", cSumAt+1, len(pkt))
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// SegmentTCP walks a TSO superpacket pkt, yielding each segment as a
|
|
||||||
// slice into pkt itself. Per-segment plaintext is laid out by sliding a
|
|
||||||
// freshly-patched copy of the L3+L4 header into pkt at offset i*gsoSize,
|
|
||||||
// where it sits immediately before that segment's payload chunk in the
|
|
||||||
// original buffer. The slide is destructive: iter i's header write overwrites
|
|
||||||
// the last hdrLen bytes of seg_{i-1}'s payload, which is dead by the time
|
|
||||||
// the next iteration begins. pkt is consumed by this call and must not be
|
|
||||||
// inspected by the caller after the final yield.
|
|
||||||
func SegmentTCP(pkt []byte, hdrLenU, csumStartU, gsoSizeU uint16, yield func(seg []byte) error) error {
|
|
||||||
if gsoSizeU == 0 {
|
|
||||||
return fmt.Errorf("gso_size is zero")
|
|
||||||
}
|
|
||||||
if csumStartU == 0 {
|
|
||||||
return fmt.Errorf("csum_start is zero")
|
|
||||||
}
|
|
||||||
|
|
||||||
headerLen := int(hdrLenU)
|
|
||||||
csumStart := int(csumStartU)
|
|
||||||
isV4 := pkt[0]>>4 == 4
|
|
||||||
|
|
||||||
tcpHdrLen := int(pkt[csumStart+tcpDataOffOff]>>4) * 4
|
|
||||||
payLen := len(pkt) - headerLen
|
|
||||||
gsoSize := int(gsoSizeU)
|
|
||||||
numSeg := (payLen + gsoSize - 1) / gsoSize
|
|
||||||
if numSeg == 0 {
|
|
||||||
numSeg = 1
|
|
||||||
}
|
|
||||||
|
|
||||||
origSeq := binary.BigEndian.Uint32(pkt[csumStart+tcpSeqOff : csumStart+tcpSeqOff+4])
|
|
||||||
origFlags := pkt[csumStart+tcpFlagsOff]
|
|
||||||
|
|
||||||
var tmp [tcpHeaderMaxLen]byte
|
|
||||||
copy(tmp[:tcpHdrLen], pkt[csumStart:headerLen])
|
|
||||||
tmp[tcpSeqOff], tmp[tcpSeqOff+1], tmp[tcpSeqOff+2], tmp[tcpSeqOff+3] = 0, 0, 0, 0
|
|
||||||
tmp[tcpFlagsOff] = 0
|
|
||||||
tmp[tcpChecksumOff], tmp[tcpChecksumOff+1] = 0, 0
|
|
||||||
baseTcpHdrSum := uint32(checksum.Checksum(tmp[:tcpHdrLen], 0))
|
|
||||||
|
|
||||||
var baseProtoSum uint32
|
|
||||||
if isV4 {
|
|
||||||
baseProtoSum = uint32(checksum.Checksum(pkt[ipv4SrcOff:ipv4AddrsEnd], 0))
|
|
||||||
} else {
|
|
||||||
baseProtoSum = uint32(checksum.Checksum(pkt[ipv6SrcOff:ipv6AddrsEnd], 0))
|
|
||||||
}
|
|
||||||
baseProtoSum += uint32(unix.IPPROTO_TCP)
|
|
||||||
|
|
||||||
var origIPID uint16
|
|
||||||
var baseIPHdrSum uint32
|
|
||||||
if isV4 {
|
|
||||||
origIPID = binary.BigEndian.Uint16(pkt[ipv4IDOff : ipv4IDOff+2])
|
|
||||||
ihl := int(pkt[0]&0x0f) * 4
|
|
||||||
if ihl < ipv4HeaderMinLen || ihl > csumStart {
|
|
||||||
return fmt.Errorf("bad IPv4 IHL: %d", ihl)
|
|
||||||
}
|
|
||||||
var ipTmp [ipv4HeaderMaxLen]byte
|
|
||||||
copy(ipTmp[:ihl], pkt[:ihl])
|
|
||||||
ipTmp[ipv4TotalLenOff], ipTmp[ipv4TotalLenOff+1] = 0, 0
|
|
||||||
ipTmp[ipv4IDOff], ipTmp[ipv4IDOff+1] = 0, 0
|
|
||||||
ipTmp[ipv4ChecksumOff], ipTmp[ipv4ChecksumOff+1] = 0, 0
|
|
||||||
baseIPHdrSum = uint32(checksum.Checksum(ipTmp[:ihl], 0))
|
|
||||||
}
|
|
||||||
|
|
||||||
for i := 0; i < numSeg; i++ {
|
|
||||||
segStart := i * gsoSize
|
|
||||||
segEnd := segStart + gsoSize
|
|
||||||
if segEnd > payLen {
|
|
||||||
segEnd = payLen
|
|
||||||
}
|
|
||||||
segPayLen := segEnd - segStart
|
|
||||||
segLen := headerLen + segPayLen
|
|
||||||
headerOff := i * gsoSize
|
|
||||||
|
|
||||||
// Slide the header into place immediately before this segment's
|
|
||||||
// payload. Iter 0's header is already at pkt[:headerLen]; for
|
|
||||||
// i ≥ 1 we copy from there. The constant-byte fields of pkt[:headerLen]
|
|
||||||
// survive iter 0's in-place patches (only seq/flags/cksum/totalLen/id
|
|
||||||
// are touched), and iter 0's stale variable-field values are
|
|
||||||
// overwritten by the per-segment patches below.
|
|
||||||
if i > 0 {
|
|
||||||
copy(pkt[headerOff:headerOff+headerLen], pkt[:headerLen])
|
|
||||||
}
|
|
||||||
seg := pkt[headerOff : headerOff+segLen]
|
|
||||||
|
|
||||||
segSeq := origSeq + uint32(segStart)
|
|
||||||
segFlags := origFlags
|
|
||||||
if i != 0 {
|
|
||||||
segFlags &^= tcpCwrFlag
|
|
||||||
}
|
|
||||||
if i != numSeg-1 {
|
|
||||||
segFlags &^= tcpFinPshMask
|
|
||||||
}
|
|
||||||
totalLen := segLen
|
|
||||||
|
|
||||||
if isV4 {
|
|
||||||
segID := origIPID + uint16(i)
|
|
||||||
binary.BigEndian.PutUint16(seg[ipv4TotalLenOff:ipv4TotalLenOff+2], uint16(totalLen))
|
|
||||||
binary.BigEndian.PutUint16(seg[ipv4IDOff:ipv4IDOff+2], segID)
|
|
||||||
ipSum := baseIPHdrSum + uint32(totalLen) + uint32(segID)
|
|
||||||
binary.BigEndian.PutUint16(seg[ipv4ChecksumOff:ipv4ChecksumOff+2], foldComplement(ipSum))
|
|
||||||
} else {
|
|
||||||
binary.BigEndian.PutUint16(seg[ipv6PayloadLenOff:ipv6PayloadLenOff+2], uint16(headerLen-ipv6FixedLen+segPayLen))
|
|
||||||
}
|
|
||||||
|
|
||||||
binary.BigEndian.PutUint32(seg[csumStart+tcpSeqOff:csumStart+tcpSeqOff+4], segSeq)
|
|
||||||
seg[csumStart+tcpFlagsOff] = segFlags
|
|
||||||
|
|
||||||
tcpLen := tcpHdrLen + segPayLen
|
|
||||||
// Payload bytes still live at their original offset in pkt. The
|
|
||||||
// header slide above only writes into pkt[i*G : i*G+H], which is
|
|
||||||
// the tail of seg_{i-1}'s payload (already consumed) and never
|
|
||||||
// overlaps seg_i's own payload at pkt[H+i*G : H+(i+1)*G].
|
|
||||||
paySum := uint32(checksum.Checksum(pkt[headerLen+segStart:headerLen+segEnd], 0))
|
|
||||||
wide := uint64(baseTcpHdrSum) + uint64(paySum) + uint64(baseProtoSum)
|
|
||||||
wide += uint64(segSeq) + uint64(segFlags) + uint64(tcpLen)
|
|
||||||
wide = (wide & 0xffffffff) + (wide >> 32)
|
|
||||||
wide = (wide & 0xffffffff) + (wide >> 32)
|
|
||||||
binary.BigEndian.PutUint16(seg[csumStart+tcpChecksumOff:csumStart+tcpChecksumOff+2], foldComplement(uint32(wide)))
|
|
||||||
|
|
||||||
if err := yield(seg); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// SegmentUDP walks a USO superpacket, sliding a per-segment-patched
|
|
||||||
// L3+L4 header into pkt at offset i*gsoSize and yielding pkt[i*G:i*G+segLen]
|
|
||||||
// to the caller. Per-segment patches are total_len + IPv4 csum (or IPv6
|
|
||||||
// payload_len) plus the UDP length and checksum. pkt is consumed
|
|
||||||
// destructively; see SegmentTCP for the layout reasoning.
|
|
||||||
//
|
|
||||||
// UDP-GSO leaves the IPv4 ID identical across segments (the kernel does not
|
|
||||||
// bump it), which is why the IP-level per-segment work is limited to
|
|
||||||
// total_len + IPv4 header checksum (v4) or payload_len (v6).
|
|
||||||
func SegmentUDP(pkt []byte, hdrLenU, csumStartU, gsoSizeU uint16, yield func(seg []byte) error) error {
|
|
||||||
if gsoSizeU == 0 {
|
|
||||||
return fmt.Errorf("gso_size is zero")
|
|
||||||
}
|
|
||||||
if csumStartU == 0 {
|
|
||||||
return fmt.Errorf("csum_start is zero")
|
|
||||||
}
|
|
||||||
|
|
||||||
isV4 := pkt[0]>>4 == 4
|
|
||||||
headerLen := int(hdrLenU)
|
|
||||||
csumStart := int(csumStartU)
|
|
||||||
if headerLen-csumStart != udpHeaderLen {
|
|
||||||
return fmt.Errorf("udp header len mismatch: %d", headerLen-csumStart)
|
|
||||||
}
|
|
||||||
|
|
||||||
payLen := len(pkt) - headerLen
|
|
||||||
gsoSize := int(gsoSizeU)
|
|
||||||
numSeg := (payLen + gsoSize - 1) / gsoSize
|
|
||||||
if numSeg == 0 {
|
|
||||||
numSeg = 1
|
|
||||||
}
|
|
||||||
|
|
||||||
var udpTmp [udpHeaderLen]byte
|
|
||||||
copy(udpTmp[:], pkt[csumStart:headerLen])
|
|
||||||
udpTmp[udpLengthOff], udpTmp[udpLengthOff+1] = 0, 0
|
|
||||||
udpTmp[udpChecksumOff], udpTmp[udpChecksumOff+1] = 0, 0
|
|
||||||
baseUDPHdrSum := uint32(checksum.Checksum(udpTmp[:], 0))
|
|
||||||
|
|
||||||
var baseProtoSum uint32
|
|
||||||
if isV4 {
|
|
||||||
baseProtoSum = uint32(checksum.Checksum(pkt[ipv4SrcOff:ipv4AddrsEnd], 0))
|
|
||||||
} else {
|
|
||||||
baseProtoSum = uint32(checksum.Checksum(pkt[ipv6SrcOff:ipv6AddrsEnd], 0))
|
|
||||||
}
|
|
||||||
baseProtoSum += uint32(unix.IPPROTO_UDP)
|
|
||||||
|
|
||||||
var baseIPHdrSum uint32
|
|
||||||
if isV4 {
|
|
||||||
ihl := int(pkt[0]&0x0f) * 4
|
|
||||||
if ihl < ipv4HeaderMinLen || ihl > csumStart {
|
|
||||||
return fmt.Errorf("bad IPv4 IHL: %d", ihl)
|
|
||||||
}
|
|
||||||
var ipTmp [ipv4HeaderMaxLen]byte
|
|
||||||
copy(ipTmp[:ihl], pkt[:ihl])
|
|
||||||
ipTmp[ipv4TotalLenOff], ipTmp[ipv4TotalLenOff+1] = 0, 0
|
|
||||||
ipTmp[ipv4ChecksumOff], ipTmp[ipv4ChecksumOff+1] = 0, 0
|
|
||||||
baseIPHdrSum = uint32(checksum.Checksum(ipTmp[:ihl], 0))
|
|
||||||
}
|
|
||||||
|
|
||||||
for i := 0; i < numSeg; i++ {
|
|
||||||
segStart := i * gsoSize
|
|
||||||
segEnd := segStart + gsoSize
|
|
||||||
if segEnd > payLen {
|
|
||||||
segEnd = payLen
|
|
||||||
}
|
|
||||||
segPayLen := segEnd - segStart
|
|
||||||
segLen := headerLen + segPayLen
|
|
||||||
headerOff := i * gsoSize
|
|
||||||
|
|
||||||
if i > 0 {
|
|
||||||
copy(pkt[headerOff:headerOff+headerLen], pkt[:headerLen])
|
|
||||||
}
|
|
||||||
seg := pkt[headerOff : headerOff+segLen]
|
|
||||||
|
|
||||||
totalLen := segLen
|
|
||||||
udpLen := udpHeaderLen + segPayLen
|
|
||||||
|
|
||||||
if isV4 {
|
|
||||||
binary.BigEndian.PutUint16(seg[ipv4TotalLenOff:ipv4TotalLenOff+2], uint16(totalLen))
|
|
||||||
ipSum := baseIPHdrSum + uint32(totalLen)
|
|
||||||
binary.BigEndian.PutUint16(seg[ipv4ChecksumOff:ipv4ChecksumOff+2], foldComplement(ipSum))
|
|
||||||
} else {
|
|
||||||
binary.BigEndian.PutUint16(seg[ipv6PayloadLenOff:ipv6PayloadLenOff+2], uint16(headerLen-ipv6FixedLen+segPayLen))
|
|
||||||
}
|
|
||||||
|
|
||||||
binary.BigEndian.PutUint16(seg[csumStart+udpLengthOff:csumStart+udpLengthOff+2], uint16(udpLen))
|
|
||||||
|
|
||||||
paySum := uint32(checksum.Checksum(pkt[headerLen+segStart:headerLen+segEnd], 0))
|
|
||||||
wide := uint64(baseUDPHdrSum) + uint64(paySum) + uint64(baseProtoSum)
|
|
||||||
wide += uint64(udpLen) + uint64(udpLen)
|
|
||||||
wide = (wide & 0xffffffff) + (wide >> 32)
|
|
||||||
wide = (wide & 0xffffffff) + (wide >> 32)
|
|
||||||
csum := foldComplement(uint32(wide))
|
|
||||||
if csum == 0 {
|
|
||||||
csum = 0xffff
|
|
||||||
}
|
|
||||||
binary.BigEndian.PutUint16(seg[csumStart+udpChecksumOff:csumStart+udpChecksumOff+2], csum)
|
|
||||||
|
|
||||||
if err := yield(seg); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// FinishChecksum computes the L4 checksum for a non-GSO packet that the kernel
|
|
||||||
// handed us with NEEDS_CSUM set. csum_start / csum_offset point at the 16-bit
|
|
||||||
// checksum field; we zero it, fold a full sum (the field was pre-loaded with
|
|
||||||
// the pseudo-header partial sum by the kernel), and store the result.
|
|
||||||
func FinishChecksum(seg []byte, hdr Hdr) error {
|
|
||||||
cs := int(hdr.CsumStart)
|
|
||||||
co := int(hdr.CsumOffset)
|
|
||||||
if cs+co+2 > len(seg) {
|
|
||||||
return fmt.Errorf("csum offsets out of range: start=%d offset=%d len=%d", cs, co, len(seg))
|
|
||||||
}
|
|
||||||
// The kernel stores a partial pseudo-header sum at [cs+co:]; sum over the
|
|
||||||
// L4 region starting at cs, folding the prior partial in as the seed.
|
|
||||||
partial := binary.BigEndian.Uint16(seg[cs+co : cs+co+2])
|
|
||||||
seg[cs+co] = 0
|
|
||||||
seg[cs+co+1] = 0
|
|
||||||
binary.BigEndian.PutUint16(seg[cs+co:cs+co+2], ^checksum.Checksum(seg[cs:], partial))
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// foldComplement folds a 32-bit one's-complement partial sum to 16 bits and
|
|
||||||
// complements it, yielding the on-wire Internet checksum value.
|
|
||||||
func foldComplement(sum uint32) uint16 {
|
|
||||||
sum = (sum & 0xffff) + (sum >> 16)
|
|
||||||
sum = (sum & 0xffff) + (sum >> 16)
|
|
||||||
return ^uint16(sum)
|
|
||||||
}
|
|
||||||
+16
-39
@@ -13,14 +13,12 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type tun struct {
|
type tun struct {
|
||||||
rwc io.ReadWriteCloser
|
io.ReadWriteCloser
|
||||||
fd int
|
fd int
|
||||||
vpnNetworks []netip.Prefix
|
vpnNetworks []netip.Prefix
|
||||||
Routes atomic.Pointer[[]Route]
|
Routes atomic.Pointer[[]Route]
|
||||||
@@ -28,37 +26,16 @@ type tun struct {
|
|||||||
l *slog.Logger
|
l *slog.Logger
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.rwc.Read(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Write(p []byte) (int, error) {
|
|
||||||
return t.rwc.Write(p)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Close() error {
|
|
||||||
return t.rwc.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func newTunFromFd(c *config.C, l *slog.Logger, deviceFd int, vpnNetworks []netip.Prefix) (*tun, error) {
|
func newTunFromFd(c *config.C, l *slog.Logger, deviceFd int, vpnNetworks []netip.Prefix) (*tun, error) {
|
||||||
// XXX Android returns an fd in non-blocking mode which is necessary for shutdown to work properly.
|
// XXX Android returns an fd in non-blocking mode which is necessary for shutdown to work properly.
|
||||||
// Be sure not to call file.Fd() as it will set the fd to blocking mode.
|
// Be sure not to call file.Fd() as it will set the fd to blocking mode.
|
||||||
file := os.NewFile(uintptr(deviceFd), "/dev/net/tun")
|
file := os.NewFile(uintptr(deviceFd), "/dev/net/tun")
|
||||||
|
|
||||||
t := &tun{
|
t := &tun{
|
||||||
rwc: file,
|
ReadWriteCloser: file,
|
||||||
fd: deviceFd,
|
fd: deviceFd,
|
||||||
vpnNetworks: vpnNetworks,
|
vpnNetworks: vpnNetworks,
|
||||||
l: l,
|
l: l,
|
||||||
}
|
}
|
||||||
|
|
||||||
err := t.reload(c, true)
|
err := t.reload(c, true)
|
||||||
@@ -85,7 +62,7 @@ func (t *tun) RoutesFor(ip netip.Addr) routing.Gateways {
|
|||||||
return r
|
return r
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Activate() error {
|
func (t tun) Activate() error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -118,18 +95,18 @@ func (t *tun) Name() string {
|
|||||||
return "android"
|
return "android"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *tun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *tun) SupportsMultiqueue() bool {
|
func (t *tun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) NewMultiQueueReader() error {
|
func (t *tun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented for android")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for android")
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,23 +0,0 @@
|
|||||||
//go:build (amd64 || arm64) && !e2e_testing
|
|
||||||
// +build amd64 arm64
|
|
||||||
// +build !e2e_testing
|
|
||||||
|
|
||||||
package overlay
|
|
||||||
|
|
||||||
import (
|
|
||||||
"log/slog"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/wfp"
|
|
||||||
)
|
|
||||||
|
|
||||||
// installInterfaceBypass installs a WFP PERMIT filter scoped to the wintun interface LUID so inbound traffic on the
|
|
||||||
// nebula adapter bypasses Windows Defender Firewall.
|
|
||||||
func installInterfaceBypass(l *slog.Logger, luid uint64) closer {
|
|
||||||
s, err := wfp.PermitInterface(luid)
|
|
||||||
if err != nil {
|
|
||||||
l.Warn("Failed to install WFP bypass filters on nebula interface", "error", err)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
l.Info("Installed WFP filters bypassing Windows Defender Firewall on nebula interface")
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
//go:build !e2e_testing
|
|
||||||
// +build !e2e_testing
|
|
||||||
|
|
||||||
package overlay
|
|
||||||
|
|
||||||
import "log/slog"
|
|
||||||
|
|
||||||
// installInterfaceBypass is a no-op on windows-386 because we don't currently build for it.
|
|
||||||
func installInterfaceBypass(_ *slog.Logger, _ uint64) closer {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
+26
-32
@@ -16,16 +16,14 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
netroute "golang.org/x/net/route"
|
netroute "golang.org/x/net/route"
|
||||||
"golang.org/x/sys/unix"
|
"golang.org/x/sys/unix"
|
||||||
)
|
)
|
||||||
|
|
||||||
type tun struct {
|
type tun struct {
|
||||||
rwc io.ReadWriteCloser
|
io.ReadWriteCloser
|
||||||
Device string
|
Device string
|
||||||
vpnNetworks []netip.Prefix
|
vpnNetworks []netip.Prefix
|
||||||
DefaultMTU int
|
DefaultMTU int
|
||||||
@@ -126,11 +124,11 @@ func newTun(c *config.C, l *slog.Logger, vpnNetworks []netip.Prefix, _ bool) (*t
|
|||||||
}
|
}
|
||||||
|
|
||||||
t := &tun{
|
t := &tun{
|
||||||
rwc: os.NewFile(uintptr(fd), ""),
|
ReadWriteCloser: os.NewFile(uintptr(fd), ""),
|
||||||
Device: name,
|
Device: name,
|
||||||
vpnNetworks: vpnNetworks,
|
vpnNetworks: vpnNetworks,
|
||||||
DefaultMTU: c.GetInt("tun.mtu", DefaultMTU),
|
DefaultMTU: c.GetInt("tun.mtu", DefaultMTU),
|
||||||
l: l,
|
l: l,
|
||||||
}
|
}
|
||||||
|
|
||||||
err = t.reload(c, true)
|
err = t.reload(c, true)
|
||||||
@@ -160,8 +158,8 @@ func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (*tun, e
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Close() error {
|
func (t *tun) Close() error {
|
||||||
if t.rwc != nil {
|
if t.ReadWriteCloser != nil {
|
||||||
return t.rwc.Close()
|
return t.ReadWriteCloser.Close()
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -504,17 +502,13 @@ func delRoute(prefix netip.Prefix, gateway netroute.Addr) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
func (t *tun) Read(to []byte) (int, error) {
|
||||||
if len(p) == 0 || len(mem) <= 4 {
|
buf := make([]byte, len(to)+4)
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
n, err := t.ReadWriteCloser.Read(buf)
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.rwc.Read(mem)
|
copy(to, buf[4:])
|
||||||
if err != nil {
|
return n - 4, err
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[4:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Write is only valid for single threaded use
|
// Write is only valid for single threaded use
|
||||||
@@ -542,7 +536,7 @@ func (t *tun) Write(from []byte) (int, error) {
|
|||||||
|
|
||||||
copy(buf[4:], from)
|
copy(buf[4:], from)
|
||||||
|
|
||||||
n, err := t.rwc.Write(buf)
|
n, err := t.ReadWriteCloser.Write(buf)
|
||||||
return n - 4, err
|
return n - 4, err
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -554,18 +548,18 @@ func (t *tun) Name() string {
|
|||||||
return t.Device
|
return t.Device
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *tun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *tun) SupportsMultiqueue() bool {
|
func (t *tun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) NewMultiQueueReader() error {
|
func (t *tun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented for darwin")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for darwin")
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
}
|
||||||
|
|||||||
+14
-36
@@ -10,9 +10,7 @@ import (
|
|||||||
|
|
||||||
"github.com/rcrowley/go-metrics"
|
"github.com/rcrowley/go-metrics"
|
||||||
"github.com/slackhq/nebula/iputil"
|
"github.com/slackhq/nebula/iputil"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type disabledTun struct {
|
type disabledTun struct {
|
||||||
@@ -20,10 +18,9 @@ type disabledTun struct {
|
|||||||
vpnNetworks []netip.Prefix
|
vpnNetworks []netip.Prefix
|
||||||
|
|
||||||
// Track these metrics since we don't have the tun device to do it for us
|
// Track these metrics since we don't have the tun device to do it for us
|
||||||
tx metrics.Counter
|
tx metrics.Counter
|
||||||
rx metrics.Counter
|
rx metrics.Counter
|
||||||
numReaders int
|
l *slog.Logger
|
||||||
l *slog.Logger
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func newDisabledTun(vpnNetworks []netip.Prefix, queueLen int, metricsEnabled bool, l *slog.Logger) *disabledTun {
|
func newDisabledTun(vpnNetworks []netip.Prefix, queueLen int, metricsEnabled bool, l *slog.Logger) *disabledTun {
|
||||||
@@ -31,7 +28,6 @@ func newDisabledTun(vpnNetworks []netip.Prefix, queueLen int, metricsEnabled boo
|
|||||||
vpnNetworks: vpnNetworks,
|
vpnNetworks: vpnNetworks,
|
||||||
read: make(chan []byte, queueLen),
|
read: make(chan []byte, queueLen),
|
||||||
l: l,
|
l: l,
|
||||||
numReaders: 1,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if metricsEnabled {
|
if metricsEnabled {
|
||||||
@@ -61,7 +57,7 @@ func (*disabledTun) Name() string {
|
|||||||
return "disabled"
|
return "disabled"
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *disabledTun) readOne(b []byte) (int, error) {
|
func (t *disabledTun) Read(b []byte) (int, error) {
|
||||||
r, ok := <-t.read
|
r, ok := <-t.read
|
||||||
if !ok {
|
if !ok {
|
||||||
return 0, io.EOF
|
return 0, io.EOF
|
||||||
@@ -79,19 +75,6 @@ func (t *disabledTun) readOne(b []byte) (int, error) {
|
|||||||
return copy(b, r), nil
|
return copy(b, r), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *disabledTun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = wire.GSOInfo{}
|
|
||||||
n, err := t.readOne(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *disabledTun) handleICMPEchoRequest(b []byte) bool {
|
func (t *disabledTun) handleICMPEchoRequest(b []byte) bool {
|
||||||
out := make([]byte, len(b))
|
out := make([]byte, len(b))
|
||||||
out = iputil.CreateICMPEchoResponse(b, out)
|
out = iputil.CreateICMPEchoResponse(b, out)
|
||||||
@@ -123,25 +106,20 @@ func (t *disabledTun) Write(b []byte) (int, error) {
|
|||||||
return len(b), nil
|
return len(b), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *disabledTun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *disabledTun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *disabledTun) SupportsMultiqueue() bool {
|
func (t *disabledTun) SupportsMultiqueue() bool {
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *disabledTun) NewMultiQueueReader() error {
|
func (t *disabledTun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
t.numReaders++
|
return t, nil
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *disabledTun) Readers() []tio.Queue {
|
|
||||||
out := make([]tio.Queue, t.numReaders)
|
|
||||||
for i := range t.numReaders {
|
|
||||||
out[i] = t
|
|
||||||
}
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *disabledTun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *disabledTun) Close() error {
|
func (t *disabledTun) Close() error {
|
||||||
|
|||||||
@@ -0,0 +1,120 @@
|
|||||||
|
//go:build linux && !android && !e2e_testing
|
||||||
|
// +build linux,!android,!e2e_testing
|
||||||
|
|
||||||
|
package overlay
|
||||||
|
|
||||||
|
import (
|
||||||
|
"errors"
|
||||||
|
"os"
|
||||||
|
"sync"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"golang.org/x/sys/unix"
|
||||||
|
)
|
||||||
|
|
||||||
|
// newReadPipe returns a read fd. The matching write fd is registered for cleanup.
|
||||||
|
// The caller takes ownership of the read fd (pass it to newTunFd / newFriend).
|
||||||
|
func newReadPipe(t *testing.T) int {
|
||||||
|
t.Helper()
|
||||||
|
var fds [2]int
|
||||||
|
if err := unix.Pipe2(fds[:], unix.O_CLOEXEC); err != nil {
|
||||||
|
t.Fatalf("pipe2: %v", err)
|
||||||
|
}
|
||||||
|
t.Cleanup(func() { _ = unix.Close(fds[1]) })
|
||||||
|
return fds[0]
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTunFile_WakeForShutdown_UnblocksRead(t *testing.T) {
|
||||||
|
tf, err := newTunFd(newReadPipe(t))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("newTunFd: %v", err)
|
||||||
|
}
|
||||||
|
t.Cleanup(func() { _ = tf.Close() })
|
||||||
|
|
||||||
|
done := make(chan error, 1)
|
||||||
|
go func() {
|
||||||
|
_, err := tf.Read(make([]byte, 64))
|
||||||
|
done <- err
|
||||||
|
}()
|
||||||
|
|
||||||
|
// Verify Read is actually blocked in poll.
|
||||||
|
select {
|
||||||
|
case err := <-done:
|
||||||
|
t.Fatalf("Read returned before shutdown signal: %v", err)
|
||||||
|
case <-time.After(50 * time.Millisecond):
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := tf.wakeForShutdown(); err != nil {
|
||||||
|
t.Fatalf("wakeForShutdown: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
select {
|
||||||
|
case err := <-done:
|
||||||
|
if !errors.Is(err, os.ErrClosed) {
|
||||||
|
t.Fatalf("expected os.ErrClosed, got %v", err)
|
||||||
|
}
|
||||||
|
case <-time.After(2 * time.Second):
|
||||||
|
t.Fatal("Read did not wake on shutdown")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTunFile_WakeForShutdown_WakesFriends(t *testing.T) {
|
||||||
|
parent, err := newTunFd(newReadPipe(t))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("newTunFd: %v", err)
|
||||||
|
}
|
||||||
|
friend, err := parent.newFriend(newReadPipe(t))
|
||||||
|
if err != nil {
|
||||||
|
_ = parent.Close()
|
||||||
|
t.Fatalf("newFriend: %v", err)
|
||||||
|
}
|
||||||
|
t.Cleanup(func() {
|
||||||
|
_ = friend.Close()
|
||||||
|
_ = parent.Close()
|
||||||
|
})
|
||||||
|
|
||||||
|
readers := []*tunFile{parent, friend}
|
||||||
|
errs := make([]error, len(readers))
|
||||||
|
var wg sync.WaitGroup
|
||||||
|
for i, r := range readers {
|
||||||
|
wg.Add(1)
|
||||||
|
go func(i int, r *tunFile) {
|
||||||
|
defer wg.Done()
|
||||||
|
_, errs[i] = r.Read(make([]byte, 64))
|
||||||
|
}(i, r)
|
||||||
|
}
|
||||||
|
|
||||||
|
time.Sleep(50 * time.Millisecond)
|
||||||
|
|
||||||
|
if err := parent.wakeForShutdown(); err != nil {
|
||||||
|
t.Fatalf("wakeForShutdown: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
done := make(chan struct{})
|
||||||
|
go func() { wg.Wait(); close(done) }()
|
||||||
|
select {
|
||||||
|
case <-done:
|
||||||
|
case <-time.After(2 * time.Second):
|
||||||
|
t.Fatal("readers did not wake")
|
||||||
|
}
|
||||||
|
|
||||||
|
for i, err := range errs {
|
||||||
|
if !errors.Is(err, os.ErrClosed) {
|
||||||
|
t.Errorf("reader %d: expected os.ErrClosed, got %v", i, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTunFile_Close_Idempotent(t *testing.T) {
|
||||||
|
tf, err := newTunFd(newReadPipe(t))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("newTunFd: %v", err)
|
||||||
|
}
|
||||||
|
if err := tf.Close(); err != nil {
|
||||||
|
t.Fatalf("first Close: %v", err)
|
||||||
|
}
|
||||||
|
if err := tf.Close(); err != nil {
|
||||||
|
t.Fatalf("second Close should be a no-op, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
+13
-26
@@ -7,6 +7,7 @@ import (
|
|||||||
"bytes"
|
"bytes"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"io/fs"
|
"io/fs"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
@@ -17,10 +18,9 @@ import (
|
|||||||
"unsafe"
|
"unsafe"
|
||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
|
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
netroute "golang.org/x/net/route"
|
netroute "golang.org/x/net/route"
|
||||||
@@ -157,20 +157,7 @@ func (t *tun) blockOnWrite() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
func (t *tun) Read(to []byte) (int, error) {
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.readOne(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) readOne(to []byte) (int, error) {
|
|
||||||
// first 4 bytes is protocol family, in network byte order
|
// first 4 bytes is protocol family, in network byte order
|
||||||
var head [4]byte
|
var head [4]byte
|
||||||
iovecs := [2]syscall.Iovec{
|
iovecs := [2]syscall.Iovec{
|
||||||
@@ -574,12 +561,20 @@ func (t *tun) Name() string {
|
|||||||
return t.Device
|
return t.Device
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *tun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *tun) SupportsMultiqueue() bool {
|
func (t *tun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) NewMultiQueueReader() error {
|
func (t *tun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented for freebsd")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for freebsd")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) addRoutes(logErrors bool) error {
|
func (t *tun) addRoutes(logErrors bool) error {
|
||||||
@@ -606,14 +601,6 @@ func (t *tun) addRoutes(logErrors bool) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) removeRoutes(routes []Route) error {
|
func (t *tun) removeRoutes(routes []Route) error {
|
||||||
for _, r := range routes {
|
for _, r := range routes {
|
||||||
if !r.Install {
|
if !r.Install {
|
||||||
|
|||||||
+25
-39
@@ -16,41 +16,18 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type tun struct {
|
type tun struct {
|
||||||
rwc io.ReadWriteCloser
|
io.ReadWriteCloser
|
||||||
vpnNetworks []netip.Prefix
|
vpnNetworks []netip.Prefix
|
||||||
Routes atomic.Pointer[[]Route]
|
Routes atomic.Pointer[[]Route]
|
||||||
routeTree atomic.Pointer[bart.Table[routing.Gateways]]
|
routeTree atomic.Pointer[bart.Table[routing.Gateways]]
|
||||||
l *slog.Logger
|
l *slog.Logger
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) <= 4 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.rwc.Read(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[4:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Write(p []byte) (int, error) {
|
|
||||||
return t.rwc.Write(p)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Close() error {
|
|
||||||
return t.rwc.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func newTun(_ *config.C, _ *slog.Logger, _ []netip.Prefix, _ bool) (*tun, error) {
|
func newTun(_ *config.C, _ *slog.Logger, _ []netip.Prefix, _ bool) (*tun, error) {
|
||||||
return nil, fmt.Errorf("newTun not supported in iOS")
|
return nil, fmt.Errorf("newTun not supported in iOS")
|
||||||
}
|
}
|
||||||
@@ -58,9 +35,9 @@ func newTun(_ *config.C, _ *slog.Logger, _ []netip.Prefix, _ bool) (*tun, error)
|
|||||||
func newTunFromFd(c *config.C, l *slog.Logger, deviceFd int, vpnNetworks []netip.Prefix) (*tun, error) {
|
func newTunFromFd(c *config.C, l *slog.Logger, deviceFd int, vpnNetworks []netip.Prefix) (*tun, error) {
|
||||||
file := os.NewFile(uintptr(deviceFd), "/dev/tun")
|
file := os.NewFile(uintptr(deviceFd), "/dev/tun")
|
||||||
t := &tun{
|
t := &tun{
|
||||||
vpnNetworks: vpnNetworks,
|
vpnNetworks: vpnNetworks,
|
||||||
rwc: &tunReadCloser{f: file},
|
ReadWriteCloser: &tunReadCloser{f: file},
|
||||||
l: l,
|
l: l,
|
||||||
}
|
}
|
||||||
|
|
||||||
err := t.reload(c, true)
|
err := t.reload(c, true)
|
||||||
@@ -119,9 +96,18 @@ type tunReadCloser struct {
|
|||||||
wBuf []byte
|
wBuf []byte
|
||||||
}
|
}
|
||||||
|
|
||||||
// Read returns a packet with the BSD 4-byte header, watch out!
|
|
||||||
func (tr *tunReadCloser) Read(to []byte) (int, error) {
|
func (tr *tunReadCloser) Read(to []byte) (int, error) {
|
||||||
return tr.f.Read(to)
|
tr.rMu.Lock()
|
||||||
|
defer tr.rMu.Unlock()
|
||||||
|
|
||||||
|
if cap(tr.rBuf) < len(to)+4 {
|
||||||
|
tr.rBuf = make([]byte, len(to)+4)
|
||||||
|
}
|
||||||
|
tr.rBuf = tr.rBuf[:len(to)+4]
|
||||||
|
|
||||||
|
n, err := tr.f.Read(tr.rBuf)
|
||||||
|
copy(to, tr.rBuf[4:])
|
||||||
|
return n - 4, err
|
||||||
}
|
}
|
||||||
|
|
||||||
func (tr *tunReadCloser) Write(from []byte) (int, error) {
|
func (tr *tunReadCloser) Write(from []byte) (int, error) {
|
||||||
@@ -165,18 +151,18 @@ func (t *tun) Name() string {
|
|||||||
return "iOS"
|
return "iOS"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *tun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *tun) SupportsMultiqueue() bool {
|
func (t *tun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) NewMultiQueueReader() error {
|
func (t *tun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented for ios")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for ios")
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
}
|
||||||
|
|||||||
+304
-165
@@ -4,7 +4,9 @@
|
|||||||
package overlay
|
package overlay
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"encoding/binary"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net"
|
"net"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
@@ -17,15 +19,180 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
"github.com/vishvananda/netlink"
|
"github.com/vishvananda/netlink"
|
||||||
"golang.org/x/sys/unix"
|
"golang.org/x/sys/unix"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// tunFile wraps a TUN file descriptor with poll-based reads. The FD provided will be changed to non-blocking.
|
||||||
|
// A shared eventfd allows Close to wake all readers blocked in poll.
|
||||||
|
type tunFile struct {
|
||||||
|
fd int
|
||||||
|
shutdownFd int
|
||||||
|
lastOne bool
|
||||||
|
readPoll [2]unix.PollFd
|
||||||
|
writePoll [2]unix.PollFd
|
||||||
|
closed bool
|
||||||
|
}
|
||||||
|
|
||||||
|
// newFriend makes a tunFile for a MultiQueueReader that copies the shutdown eventfd from the parent tun
|
||||||
|
func (r *tunFile) newFriend(fd int) (*tunFile, error) {
|
||||||
|
if err := unix.SetNonblock(fd, true); err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to set tun fd non-blocking: %w", err)
|
||||||
|
}
|
||||||
|
return &tunFile{
|
||||||
|
fd: fd,
|
||||||
|
shutdownFd: r.shutdownFd,
|
||||||
|
readPoll: [2]unix.PollFd{
|
||||||
|
{Fd: int32(fd), Events: unix.POLLIN},
|
||||||
|
{Fd: int32(r.shutdownFd), Events: unix.POLLIN},
|
||||||
|
},
|
||||||
|
writePoll: [2]unix.PollFd{
|
||||||
|
{Fd: int32(fd), Events: unix.POLLOUT},
|
||||||
|
{Fd: int32(r.shutdownFd), Events: unix.POLLIN},
|
||||||
|
},
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func newTunFd(fd int) (*tunFile, error) {
|
||||||
|
if err := unix.SetNonblock(fd, true); err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to set tun fd non-blocking: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
shutdownFd, err := unix.Eventfd(0, unix.EFD_NONBLOCK|unix.EFD_CLOEXEC)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to create eventfd: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
out := &tunFile{
|
||||||
|
fd: fd,
|
||||||
|
shutdownFd: shutdownFd,
|
||||||
|
lastOne: true,
|
||||||
|
readPoll: [2]unix.PollFd{
|
||||||
|
{Fd: int32(fd), Events: unix.POLLIN},
|
||||||
|
{Fd: int32(shutdownFd), Events: unix.POLLIN},
|
||||||
|
},
|
||||||
|
writePoll: [2]unix.PollFd{
|
||||||
|
{Fd: int32(fd), Events: unix.POLLOUT},
|
||||||
|
{Fd: int32(shutdownFd), Events: unix.POLLIN},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
return out, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *tunFile) blockOnRead() error {
|
||||||
|
const problemFlags = unix.POLLHUP | unix.POLLNVAL | unix.POLLERR
|
||||||
|
var err error
|
||||||
|
for {
|
||||||
|
_, err = unix.Poll(r.readPoll[:], -1)
|
||||||
|
if err != unix.EINTR {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
//always reset these!
|
||||||
|
tunEvents := r.readPoll[0].Revents
|
||||||
|
shutdownEvents := r.readPoll[1].Revents
|
||||||
|
r.readPoll[0].Revents = 0
|
||||||
|
r.readPoll[1].Revents = 0
|
||||||
|
//do the err check before trusting the potentially bogus bits we just got
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if shutdownEvents&(unix.POLLIN|problemFlags) != 0 {
|
||||||
|
return os.ErrClosed
|
||||||
|
} else if tunEvents&problemFlags != 0 {
|
||||||
|
return os.ErrClosed
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *tunFile) blockOnWrite() error {
|
||||||
|
const problemFlags = unix.POLLHUP | unix.POLLNVAL | unix.POLLERR
|
||||||
|
var err error
|
||||||
|
for {
|
||||||
|
_, err = unix.Poll(r.writePoll[:], -1)
|
||||||
|
if err != unix.EINTR {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
//always reset these!
|
||||||
|
tunEvents := r.writePoll[0].Revents
|
||||||
|
shutdownEvents := r.writePoll[1].Revents
|
||||||
|
r.writePoll[0].Revents = 0
|
||||||
|
r.writePoll[1].Revents = 0
|
||||||
|
//do the err check before trusting the potentially bogus bits we just got
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if shutdownEvents&(unix.POLLIN|problemFlags) != 0 {
|
||||||
|
return os.ErrClosed
|
||||||
|
} else if tunEvents&problemFlags != 0 {
|
||||||
|
return os.ErrClosed
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *tunFile) Read(buf []byte) (int, error) {
|
||||||
|
for {
|
||||||
|
if n, err := unix.Read(r.fd, buf); err == nil {
|
||||||
|
return n, nil
|
||||||
|
} else if err == unix.EAGAIN {
|
||||||
|
if err = r.blockOnRead(); err != nil {
|
||||||
|
return 0, err
|
||||||
|
}
|
||||||
|
continue
|
||||||
|
} else if err == unix.EINTR {
|
||||||
|
continue
|
||||||
|
} else if err == unix.EBADF {
|
||||||
|
return 0, os.ErrClosed
|
||||||
|
} else {
|
||||||
|
return 0, err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *tunFile) Write(buf []byte) (int, error) {
|
||||||
|
for {
|
||||||
|
if n, err := unix.Write(r.fd, buf); err == nil {
|
||||||
|
return n, nil
|
||||||
|
} else if err == unix.EAGAIN {
|
||||||
|
if err = r.blockOnWrite(); err != nil {
|
||||||
|
return 0, err
|
||||||
|
}
|
||||||
|
continue
|
||||||
|
} else if err == unix.EINTR {
|
||||||
|
continue
|
||||||
|
} else if err == unix.EBADF {
|
||||||
|
return 0, os.ErrClosed
|
||||||
|
} else {
|
||||||
|
return 0, err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *tunFile) wakeForShutdown() error {
|
||||||
|
var buf [8]byte
|
||||||
|
binary.NativeEndian.PutUint64(buf[:], 1)
|
||||||
|
_, err := unix.Write(int(r.readPoll[1].Fd), buf[:])
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *tunFile) Close() error {
|
||||||
|
if r.closed { // avoid closing more than once. Technically a fd could get re-used, which would be a problem
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
r.closed = true
|
||||||
|
if r.lastOne {
|
||||||
|
_ = unix.Close(r.shutdownFd)
|
||||||
|
}
|
||||||
|
return unix.Close(r.fd)
|
||||||
|
}
|
||||||
|
|
||||||
type tun struct {
|
type tun struct {
|
||||||
readers tio.QueueSet
|
*tunFile
|
||||||
|
readers []*tunFile
|
||||||
closeLock sync.Mutex
|
closeLock sync.Mutex
|
||||||
Device string
|
Device string
|
||||||
vpnNetworks []netip.Prefix
|
vpnNetworks []netip.Prefix
|
||||||
@@ -34,14 +201,6 @@ type tun struct {
|
|||||||
TXQueueLen int
|
TXQueueLen int
|
||||||
deviceIndex int
|
deviceIndex int
|
||||||
ioctlFd uintptr
|
ioctlFd uintptr
|
||||||
vnetHdr bool
|
|
||||||
// routeFeatureECN, when true, sets RTAX_FEATURE_ECN on every route we
|
|
||||||
// install for the tun. The kernel then actively negotiates ECN for
|
|
||||||
// connections destined to those prefixes (equivalent to `ip route
|
|
||||||
// change ... features ecn`) regardless of net.ipv4.tcp_ecn, so flows
|
|
||||||
// across the nebula mesh use ECN even when the host default is the
|
|
||||||
// passive setting (=2). Disable via tunnels.ecn=false.
|
|
||||||
routeFeatureECN bool
|
|
||||||
|
|
||||||
Routes atomic.Pointer[[]Route]
|
Routes atomic.Pointer[[]Route]
|
||||||
routeTree atomic.Pointer[bart.Table[routing.Gateways]]
|
routeTree atomic.Pointer[bart.Table[routing.Gateways]]
|
||||||
@@ -80,9 +239,7 @@ type ifreqQLEN struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func newTunFromFd(c *config.C, l *slog.Logger, deviceFd int, vpnNetworks []netip.Prefix) (*tun, error) {
|
func newTunFromFd(c *config.C, l *slog.Logger, deviceFd int, vpnNetworks []netip.Prefix) (*tun, error) {
|
||||||
// We don't know what flags the caller opened this fd with and can't turn
|
t, err := newTunGeneric(c, l, deviceFd, vpnNetworks)
|
||||||
// on IFF_VNET_HDR after TUNSETIFF, so skip offload on inherited fds.
|
|
||||||
t, err := newTunGeneric(c, l, deviceFd, false, false, vpnNetworks)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -92,105 +249,46 @@ func newTunFromFd(c *config.C, l *slog.Logger, deviceFd int, vpnNetworks []netip
|
|||||||
return t, nil
|
return t, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// openTunDev opens /dev/net/tun, creating the device node first if it's
|
|
||||||
// missing (docker containers occasionally omit it).
|
|
||||||
func openTunDev() (int, error) {
|
|
||||||
fd, err := unix.Open("/dev/net/tun", os.O_RDWR, 0)
|
|
||||||
if err == nil {
|
|
||||||
return fd, nil
|
|
||||||
}
|
|
||||||
if !os.IsNotExist(err) {
|
|
||||||
return -1, err
|
|
||||||
}
|
|
||||||
if err = os.MkdirAll("/dev/net", 0755); err != nil {
|
|
||||||
return -1, fmt.Errorf("/dev/net/tun doesn't exist, failed to mkdir -p /dev/net: %w", err)
|
|
||||||
}
|
|
||||||
if err = unix.Mknod("/dev/net/tun", unix.S_IFCHR|0600, int(unix.Mkdev(10, 200))); err != nil {
|
|
||||||
return -1, fmt.Errorf("failed to create /dev/net/tun: %w", err)
|
|
||||||
}
|
|
||||||
fd, err = unix.Open("/dev/net/tun", os.O_RDWR, 0)
|
|
||||||
if err != nil {
|
|
||||||
return -1, fmt.Errorf("created /dev/net/tun, but still failed: %w", err)
|
|
||||||
}
|
|
||||||
return fd, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// tunSetIff runs TUNSETIFF with the given flags and returns the kernel-chosen
|
|
||||||
// device name on success.
|
|
||||||
func tunSetIff(fd int, name string, flags uint16) (string, error) {
|
|
||||||
var req ifReq
|
|
||||||
req.Flags = flags
|
|
||||||
copy(req.Name[:], name)
|
|
||||||
if err := ioctl(uintptr(fd), uintptr(unix.TUNSETIFF), uintptr(unsafe.Pointer(&req))); err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
return strings.Trim(string(req.Name[:]), "\x00"), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// tsoOffloadFlags are the TUN_F_* bits we ask the kernel to enable when a
|
|
||||||
// TSO-capable TUN is available. CSUM is required as a prerequisite for TSO.
|
|
||||||
// TSO_ECN tells the kernel we propagate ECN correctly through coalesce and
|
|
||||||
// segmentation, so it can deliver superpackets whose seed has CWR/ECE set
|
|
||||||
// or whose IP-level codepoint is CE.
|
|
||||||
const tsoOffloadFlags = unix.TUN_F_CSUM | unix.TUN_F_TSO4 | unix.TUN_F_TSO6 | unix.TUN_F_TSO_ECN
|
|
||||||
|
|
||||||
// usoOffloadFlags adds UDP Segmentation Offload to tsoOffloadFlags. Requires
|
|
||||||
// Linux ≥ 6.2; older kernels reject it and we fall back to TCP-only TSO via
|
|
||||||
// tsoOffloadFlags.
|
|
||||||
const usoOffloadFlags = tsoOffloadFlags | unix.TUN_F_USO4 | unix.TUN_F_USO6
|
|
||||||
|
|
||||||
func newTun(c *config.C, l *slog.Logger, vpnNetworks []netip.Prefix, multiqueue bool) (*tun, error) {
|
func newTun(c *config.C, l *slog.Logger, vpnNetworks []netip.Prefix, multiqueue bool) (*tun, error) {
|
||||||
baseFlags := uint16(unix.IFF_TUN | unix.IFF_NO_PI)
|
fd, err := unix.Open("/dev/net/tun", os.O_RDWR, 0)
|
||||||
if multiqueue {
|
|
||||||
baseFlags |= unix.IFF_MULTI_QUEUE
|
|
||||||
}
|
|
||||||
nameStr := c.GetString("tun.dev", "")
|
|
||||||
|
|
||||||
// First try to enable IFF_VNET_HDR via TUNSETIFF and negotiate TUN_F_*
|
|
||||||
// offloads via TUNSETOFFLOAD so we can receive TSO/USO superpackets.
|
|
||||||
// We try TSO+USO first, fall back to TSO-only on kernels without USO
|
|
||||||
// (Linux < 6.2), and finally give up on virtio headers entirely and
|
|
||||||
// reopen as a plain TUN if neither offload mask is accepted.
|
|
||||||
fd, err := openTunDev()
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
// If /dev/net/tun doesn't exist, try to create it (will happen in docker)
|
||||||
}
|
if os.IsNotExist(err) {
|
||||||
vnetHdr := true
|
err = os.MkdirAll("/dev/net", 0755)
|
||||||
usoEnabled := false
|
if err != nil {
|
||||||
name, err := tunSetIff(fd, nameStr, baseFlags|unix.IFF_VNET_HDR)
|
return nil, fmt.Errorf("/dev/net/tun doesn't exist, failed to mkdir -p /dev/net: %w", err)
|
||||||
if err != nil {
|
}
|
||||||
_ = unix.Close(fd)
|
err = unix.Mknod("/dev/net/tun", unix.S_IFCHR|0600, int(unix.Mkdev(10, 200)))
|
||||||
vnetHdr = false
|
if err != nil {
|
||||||
} else {
|
return nil, fmt.Errorf("failed to create /dev/net/tun: %w", err)
|
||||||
// Try TSO+USO first. On kernels without USO support (Linux < 6.2)
|
}
|
||||||
// the ioctl returns EINVAL; fall back to the TCP-only mask before
|
|
||||||
// giving up on VNET_HDR entirely.
|
|
||||||
if err = ioctl(uintptr(fd), unix.TUNSETOFFLOAD, uintptr(usoOffloadFlags)); err == nil {
|
|
||||||
usoEnabled = true
|
|
||||||
} else if err = ioctl(uintptr(fd), unix.TUNSETOFFLOAD, uintptr(tsoOffloadFlags)); err != nil {
|
|
||||||
l.Warn("Failed to enable TUN offload (TSO); proceeding without virtio headers", "error", err)
|
|
||||||
_ = unix.Close(fd)
|
|
||||||
vnetHdr = false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if !vnetHdr {
|
fd, err = unix.Open("/dev/net/tun", os.O_RDWR, 0)
|
||||||
fd, err = openTunDev()
|
if err != nil {
|
||||||
if err != nil {
|
return nil, fmt.Errorf("created /dev/net/tun, but still failed: %w", err)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
name, err = tunSetIff(fd, nameStr, baseFlags)
|
}
|
||||||
if err != nil {
|
|
||||||
_ = unix.Close(fd)
|
var req ifReq
|
||||||
return nil, &NameError{Name: nameStr, Underlying: err}
|
req.Flags = uint16(unix.IFF_TUN | unix.IFF_NO_PI)
|
||||||
|
if multiqueue {
|
||||||
|
req.Flags |= unix.IFF_MULTI_QUEUE
|
||||||
|
}
|
||||||
|
nameStr := c.GetString("tun.dev", "")
|
||||||
|
copy(req.Name[:], nameStr)
|
||||||
|
if err = ioctl(uintptr(fd), uintptr(unix.TUNSETIFF), uintptr(unsafe.Pointer(&req))); err != nil {
|
||||||
|
_ = unix.Close(fd)
|
||||||
|
return nil, &NameError{
|
||||||
|
Name: nameStr,
|
||||||
|
Underlying: err,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
name := strings.Trim(string(req.Name[:]), "\x00")
|
||||||
|
|
||||||
if vnetHdr {
|
t, err := newTunGeneric(c, l, fd, vpnNetworks)
|
||||||
l.Info("TUN offload enabled", "tso", true, "uso", usoEnabled)
|
|
||||||
}
|
|
||||||
|
|
||||||
t, err := newTunGeneric(c, l, fd, vnetHdr, usoEnabled, vpnNetworks)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -201,34 +299,20 @@ func newTun(c *config.C, l *slog.Logger, vpnNetworks []netip.Prefix, multiqueue
|
|||||||
}
|
}
|
||||||
|
|
||||||
// newTunGeneric does all the stuff common to different tun initialization paths. It will close your files on error.
|
// newTunGeneric does all the stuff common to different tun initialization paths. It will close your files on error.
|
||||||
func newTunGeneric(c *config.C, l *slog.Logger, fd int, vnetHdr, usoEnabled bool, vpnNetworks []netip.Prefix) (*tun, error) {
|
func newTunGeneric(c *config.C, l *slog.Logger, fd int, vpnNetworks []netip.Prefix) (*tun, error) {
|
||||||
var qs tio.QueueSet
|
tfd, err := newTunFd(fd)
|
||||||
var err error
|
|
||||||
if vnetHdr {
|
|
||||||
qs, err = tio.NewOffloadQueueSet(usoEnabled)
|
|
||||||
} else {
|
|
||||||
qs, err = tio.NewPollQueueSet()
|
|
||||||
}
|
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
_ = unix.Close(fd)
|
_ = unix.Close(fd)
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
err = qs.Add(fd)
|
|
||||||
if err != nil {
|
|
||||||
_ = unix.Close(fd)
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
t := &tun{
|
t := &tun{
|
||||||
readers: qs,
|
tunFile: tfd,
|
||||||
|
readers: []*tunFile{tfd},
|
||||||
closeLock: sync.Mutex{},
|
closeLock: sync.Mutex{},
|
||||||
vnetHdr: vnetHdr,
|
|
||||||
vpnNetworks: vpnNetworks,
|
vpnNetworks: vpnNetworks,
|
||||||
TXQueueLen: c.GetInt("tun.tx_queue", 500),
|
TXQueueLen: c.GetInt("tun.tx_queue", 500),
|
||||||
useSystemRoutes: c.GetBool("tun.use_system_route_table", false),
|
useSystemRoutes: c.GetBool("tun.use_system_route_table", false),
|
||||||
useSystemRoutesBufferSize: c.GetInt("tun.use_system_route_table_buffer_size", 0),
|
useSystemRoutesBufferSize: c.GetInt("tun.use_system_route_table_buffer_size", 0),
|
||||||
routeFeatureECN: c.GetBool("tunnels.ecn", true),
|
|
||||||
routesFromSystem: map[netip.Prefix]routing.Gateways{},
|
routesFromSystem: map[netip.Prefix]routing.Gateways{},
|
||||||
l: l,
|
l: l,
|
||||||
}
|
}
|
||||||
@@ -284,6 +368,13 @@ func (t *tun) reload(c *config.C, initial bool) error {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// tun.max_mtu raises the device MTU above tun.mtu so PMTUD has headroom to
|
||||||
|
// install per-peer routes between tun.mtu (floor) and tun.max_mtu (ceiling).
|
||||||
|
// When unset (default 0) the device MTU is unchanged from existing behavior.
|
||||||
|
if pmtudCeiling := c.GetInt("tun.max_mtu", 0); pmtudCeiling > newMaxMTU {
|
||||||
|
newMaxMTU = pmtudCeiling
|
||||||
|
}
|
||||||
|
|
||||||
t.MaxMTU = newMaxMTU
|
t.MaxMTU = newMaxMTU
|
||||||
t.DefaultMTU = newDefaultMTU
|
t.DefaultMTU = newDefaultMTU
|
||||||
|
|
||||||
@@ -326,38 +417,32 @@ func (t *tun) SupportsMultiqueue() bool {
|
|||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) NewMultiQueueReader() error {
|
func (t *tun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
t.closeLock.Lock()
|
t.closeLock.Lock()
|
||||||
defer t.closeLock.Unlock()
|
defer t.closeLock.Unlock()
|
||||||
|
|
||||||
fd, err := unix.Open("/dev/net/tun", os.O_RDWR, 0)
|
fd, err := unix.Open("/dev/net/tun", os.O_RDWR, 0)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
flags := uint16(unix.IFF_TUN | unix.IFF_NO_PI | unix.IFF_MULTI_QUEUE)
|
var req ifReq
|
||||||
if t.vnetHdr {
|
req.Flags = uint16(unix.IFF_TUN | unix.IFF_NO_PI | unix.IFF_MULTI_QUEUE)
|
||||||
flags |= unix.IFF_VNET_HDR
|
copy(req.Name[:], t.Device)
|
||||||
}
|
if err = ioctl(uintptr(fd), uintptr(unix.TUNSETIFF), uintptr(unsafe.Pointer(&req))); err != nil {
|
||||||
if _, err = tunSetIff(fd, t.Device, flags); err != nil {
|
|
||||||
_ = unix.Close(fd)
|
_ = unix.Close(fd)
|
||||||
return err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
if t.vnetHdr {
|
out, err := t.tunFile.newFriend(fd)
|
||||||
if err = ioctl(uintptr(fd), unix.TUNSETOFFLOAD, uintptr(tsoOffloadFlags)); err != nil {
|
|
||||||
_ = unix.Close(fd)
|
|
||||||
return fmt.Errorf("failed to enable offload on multiqueue tun fd: %w", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
err = t.readers.Add(fd)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
_ = unix.Close(fd)
|
_ = unix.Close(fd)
|
||||||
return err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
return nil
|
t.readers = append(t.readers, out)
|
||||||
|
|
||||||
|
return out, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) RoutesFor(ip netip.Addr) routing.Gateways {
|
func (t *tun) RoutesFor(ip netip.Addr) routing.Gateways {
|
||||||
@@ -518,25 +603,13 @@ func (t *tun) setDefaultRoute(cidr netip.Prefix) error {
|
|||||||
LinkIndex: t.deviceIndex,
|
LinkIndex: t.deviceIndex,
|
||||||
Dst: dr,
|
Dst: dr,
|
||||||
MTU: t.DefaultMTU,
|
MTU: t.DefaultMTU,
|
||||||
AdvMSS: t.advMSS(Route{}),
|
AdvMSS: t.advMSS(Route{Cidr: cidr}),
|
||||||
Scope: unix.RT_SCOPE_LINK,
|
Scope: unix.RT_SCOPE_LINK,
|
||||||
Src: net.IP(cidr.Addr().AsSlice()),
|
Src: net.IP(cidr.Addr().AsSlice()),
|
||||||
Protocol: unix.RTPROT_KERNEL,
|
Protocol: unix.RTPROT_KERNEL,
|
||||||
Table: unix.RT_TABLE_MAIN,
|
Table: unix.RT_TABLE_MAIN,
|
||||||
Type: unix.RTN_UNICAST,
|
Type: unix.RTN_UNICAST,
|
||||||
}
|
}
|
||||||
// Match the metric the kernel uses for its auto-installed connected
|
|
||||||
// route, so RouteReplace overwrites it in place instead of adding a
|
|
||||||
// second route at a worse metric. IPv6 connected routes are installed
|
|
||||||
// at metric 256 (IP6_RT_PRIO_KERN); IPv4 uses 0. Without this, the
|
|
||||||
// kernel route wins lookups and our MTU / AdvMSS / Features never
|
|
||||||
// apply on v6.
|
|
||||||
if cidr.Addr().Is6() {
|
|
||||||
nr.Priority = 256
|
|
||||||
}
|
|
||||||
if t.routeFeatureECN {
|
|
||||||
nr.Features |= unix.RTAX_FEATURE_ECN
|
|
||||||
}
|
|
||||||
err := netlink.RouteReplace(&nr)
|
err := netlink.RouteReplace(&nr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.l.Warn("Failed to set default route MTU, retrying", "error", err, "cidr", cidr)
|
t.l.Warn("Failed to set default route MTU, retrying", "error", err, "cidr", cidr)
|
||||||
@@ -586,9 +659,6 @@ func (t *tun) addRoutes(logErrors bool) error {
|
|||||||
if r.Metric > 0 {
|
if r.Metric > 0 {
|
||||||
nr.Priority = r.Metric
|
nr.Priority = r.Metric
|
||||||
}
|
}
|
||||||
if t.routeFeatureECN {
|
|
||||||
nr.Features |= unix.RTAX_FEATURE_ECN
|
|
||||||
}
|
|
||||||
|
|
||||||
err := netlink.RouteReplace(&nr)
|
err := netlink.RouteReplace(&nr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -642,17 +712,68 @@ func (t *tun) Name() string {
|
|||||||
return t.Device
|
return t.Device
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) SupportsPerPeerMTU() bool {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
|
// SetPeerMTU installs a host route (/32 for an IPv4 vpn address, /128 for an IPv6
|
||||||
|
// vpn address) to addr through this tun device with the given MTU. This causes
|
||||||
|
// the kernel to reject (or surface PTB to apps for) inside packets to addr that
|
||||||
|
// would exceed mtu. Pass mtu=0 to remove the override and let the per-vpn-network
|
||||||
|
// route apply again. PoC: assumes addr is reachable directly via this device.
|
||||||
|
func (t *tun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
bits := addr.BitLen()
|
||||||
|
prefix := netip.PrefixFrom(addr, bits)
|
||||||
|
|
||||||
|
dr := &net.IPNet{
|
||||||
|
IP: addr.AsSlice(),
|
||||||
|
Mask: net.CIDRMask(bits, bits),
|
||||||
|
}
|
||||||
|
|
||||||
|
if mtu == 0 {
|
||||||
|
nr := netlink.Route{
|
||||||
|
LinkIndex: t.deviceIndex,
|
||||||
|
Dst: dr,
|
||||||
|
Scope: unix.RT_SCOPE_LINK,
|
||||||
|
}
|
||||||
|
if err := netlink.RouteDel(&nr); err != nil {
|
||||||
|
return fmt.Errorf("failed to remove per-peer mtu route %v: %w", prefix, err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
nr := netlink.Route{
|
||||||
|
LinkIndex: t.deviceIndex,
|
||||||
|
Dst: dr,
|
||||||
|
MTU: mtu,
|
||||||
|
AdvMSS: t.advMSS(Route{Cidr: prefix, MTU: mtu}),
|
||||||
|
Scope: unix.RT_SCOPE_LINK,
|
||||||
|
}
|
||||||
|
if err := netlink.RouteReplace(&nr); err != nil {
|
||||||
|
return fmt.Errorf("failed to set per-peer mtu route %v mtu=%d: %w", prefix, mtu, err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *tun) advMSS(r Route) int {
|
func (t *tun) advMSS(r Route) int {
|
||||||
mtu := r.MTU
|
mtu := r.MTU
|
||||||
if r.MTU == 0 {
|
if r.MTU == 0 {
|
||||||
mtu = t.DefaultMTU
|
mtu = t.DefaultMTU
|
||||||
}
|
}
|
||||||
|
|
||||||
// We only need to set advmss if the route MTU does not match the device MTU
|
// We only need to set advmss if the route MTU does not match the device MTU.
|
||||||
if mtu != t.MaxMTU {
|
if mtu == t.MaxMTU {
|
||||||
return mtu - 40
|
return 0
|
||||||
}
|
}
|
||||||
return 0
|
|
||||||
|
// MSS = MTU - (IP header + TCP header). TCP is always 20 bytes; IP is 20 for
|
||||||
|
// v4 and 40 for v6. r.Cidr is the route destination so it tells us which
|
||||||
|
// family this route is in. If Cidr is unset (empty Route) we default to v4.
|
||||||
|
addr := r.Cidr.Addr()
|
||||||
|
if addr.Is6() && !addr.Is4In6() {
|
||||||
|
return mtu - 60
|
||||||
|
}
|
||||||
|
return mtu - 40
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) watchRoutes() {
|
func (t *tun) watchRoutes() {
|
||||||
@@ -806,10 +927,6 @@ func (t *tun) updateRoutes(r netlink.RouteUpdate) {
|
|||||||
t.routeTree.Store(newTree)
|
t.routeTree.Store(newTree)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Readers() []tio.Queue {
|
|
||||||
return t.readers.Queues()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Close() error {
|
func (t *tun) Close() error {
|
||||||
t.closeLock.Lock()
|
t.closeLock.Lock()
|
||||||
defer t.closeLock.Unlock()
|
defer t.closeLock.Unlock()
|
||||||
@@ -819,10 +936,32 @@ func (t *tun) Close() error {
|
|||||||
t.routeChan = nil
|
t.routeChan = nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Signal all readers blocked in poll to wake up and exit
|
||||||
|
_ = t.tunFile.wakeForShutdown()
|
||||||
|
|
||||||
if t.ioctlFd > 0 {
|
if t.ioctlFd > 0 {
|
||||||
_ = unix.Close(int(t.ioctlFd))
|
_ = unix.Close(int(t.ioctlFd))
|
||||||
t.ioctlFd = 0
|
t.ioctlFd = 0
|
||||||
}
|
}
|
||||||
|
|
||||||
return t.readers.Close()
|
for i := range t.readers {
|
||||||
|
if i == 0 {
|
||||||
|
continue //we want to close the zeroth reader last
|
||||||
|
}
|
||||||
|
err := t.readers[i].Close()
|
||||||
|
if err != nil {
|
||||||
|
t.l.Error("error closing tun reader", "reader", i, "error", err)
|
||||||
|
} else {
|
||||||
|
t.l.Info("closed tun reader", "reader", i)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
//this is t.readers[0] too
|
||||||
|
err := t.tunFile.Close()
|
||||||
|
if err != nil {
|
||||||
|
t.l.Error("error closing tun reader", "reader", 0, "error", err)
|
||||||
|
} else {
|
||||||
|
t.l.Info("closed tun reader", "reader", 0)
|
||||||
|
}
|
||||||
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,9 +3,7 @@
|
|||||||
|
|
||||||
package overlay
|
package overlay
|
||||||
|
|
||||||
import (
|
import "testing"
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
var runAdvMSSTests = []struct {
|
var runAdvMSSTests = []struct {
|
||||||
name string
|
name string
|
||||||
|
|||||||
+12
-26
@@ -6,6 +6,7 @@ package overlay
|
|||||||
import (
|
import (
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
@@ -16,10 +17,8 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
netroute "golang.org/x/net/route"
|
netroute "golang.org/x/net/route"
|
||||||
"golang.org/x/sys/unix"
|
"golang.org/x/sys/unix"
|
||||||
)
|
)
|
||||||
@@ -69,27 +68,6 @@ type tun struct {
|
|||||||
fd int
|
fd int
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.readOne(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
|
||||||
|
|
||||||
var deviceNameRE = regexp.MustCompile(`^tun[0-9]+$`)
|
var deviceNameRE = regexp.MustCompile(`^tun[0-9]+$`)
|
||||||
|
|
||||||
func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (*tun, error) {
|
func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (*tun, error) {
|
||||||
@@ -163,7 +141,7 @@ func (t *tun) Close() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) readOne(to []byte) (int, error) {
|
func (t *tun) Read(to []byte) (int, error) {
|
||||||
rc, err := t.f.SyscallConn()
|
rc, err := t.f.SyscallConn()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return 0, fmt.Errorf("failed to get syscall conn for tun: %w", err)
|
return 0, fmt.Errorf("failed to get syscall conn for tun: %w", err)
|
||||||
@@ -412,12 +390,20 @@ func (t *tun) Name() string {
|
|||||||
return t.Device
|
return t.Device
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *tun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *tun) SupportsMultiqueue() bool {
|
func (t *tun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) NewMultiQueueReader() error {
|
func (t *tun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented for netbsd")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for netbsd")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) addRoutes(logErrors bool) error {
|
func (t *tun) addRoutes(logErrors bool) error {
|
||||||
|
|||||||
+20
-25
@@ -6,6 +6,7 @@ package overlay
|
|||||||
import (
|
import (
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
@@ -16,10 +17,8 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
netroute "golang.org/x/net/route"
|
netroute "golang.org/x/net/route"
|
||||||
"golang.org/x/sys/unix"
|
"golang.org/x/sys/unix"
|
||||||
)
|
)
|
||||||
@@ -62,19 +61,6 @@ type tun struct {
|
|||||||
out []byte
|
out []byte
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) <= 4 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.f.Read(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[4:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var deviceNameRE = regexp.MustCompile(`^tun[0-9]+$`)
|
var deviceNameRE = regexp.MustCompile(`^tun[0-9]+$`)
|
||||||
|
|
||||||
func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (*tun, error) {
|
func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (*tun, error) {
|
||||||
@@ -138,6 +124,15 @@ func (t *tun) Close() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) Read(to []byte) (int, error) {
|
||||||
|
buf := make([]byte, len(to)+4)
|
||||||
|
|
||||||
|
n, err := t.f.Read(buf)
|
||||||
|
|
||||||
|
copy(to, buf[4:])
|
||||||
|
return n - 4, err
|
||||||
|
}
|
||||||
|
|
||||||
// Write is only valid for single threaded use
|
// Write is only valid for single threaded use
|
||||||
func (t *tun) Write(from []byte) (int, error) {
|
func (t *tun) Write(from []byte) (int, error) {
|
||||||
buf := t.out
|
buf := t.out
|
||||||
@@ -315,12 +310,20 @@ func (t *tun) Name() string {
|
|||||||
return t.Device
|
return t.Device
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *tun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *tun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *tun) SupportsMultiqueue() bool {
|
func (t *tun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) NewMultiQueueReader() error {
|
func (t *tun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented for openbsd")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for openbsd")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) addRoutes(logErrors bool) error {
|
func (t *tun) addRoutes(logErrors bool) error {
|
||||||
@@ -371,14 +374,6 @@ func (t *tun) deviceBytes() (o [16]byte) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *tun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *tun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
|
||||||
|
|
||||||
func addRoute(prefix netip.Prefix, gateways []netip.Prefix) error {
|
func addRoute(prefix netip.Prefix, gateways []netip.Prefix) error {
|
||||||
sock, err := unix.Socket(unix.AF_ROUTE, unix.SOCK_RAW, unix.AF_UNSPEC)
|
sock, err := unix.Socket(unix.AF_ROUTE, unix.SOCK_RAW, unix.AF_UNSPEC)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
+16
-75
@@ -14,10 +14,7 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/udp"
|
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type TestTun struct {
|
type TestTun struct {
|
||||||
@@ -57,12 +54,9 @@ func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (*TestTu
|
|||||||
return nil, fmt.Errorf("newTunFromFd not supported")
|
return nil, fmt.Errorf("newTunFromFd not supported")
|
||||||
}
|
}
|
||||||
|
|
||||||
// Send will place a byte array onto the receive queue for nebula to consume.
|
// Send will place a byte array onto the receive queue for nebula to consume
|
||||||
// These are unencrypted ip layer frames destined for another nebula node.
|
// These are unencrypted ip layer frames destined for another nebula node.
|
||||||
// packets should exit the udp side, capture them with udpConn.Get.
|
// packets should exit the udp side, capture them with udpConn.Get
|
||||||
//
|
|
||||||
// Send copies the input via the freelist, so the caller is free to mutate
|
|
||||||
// or reuse it after the call returns.
|
|
||||||
func (t *TestTun) Send(packet []byte) {
|
func (t *TestTun) Send(packet []byte) {
|
||||||
if t.closed.Load() {
|
if t.closed.Load() {
|
||||||
return
|
return
|
||||||
@@ -71,9 +65,7 @@ func (t *TestTun) Send(packet []byte) {
|
|||||||
if t.l.Enabled(context.Background(), slog.LevelDebug) {
|
if t.l.Enabled(context.Background(), slog.LevelDebug) {
|
||||||
t.l.Debug("Tun receiving injected packet", "dataLen", len(packet))
|
t.l.Debug("Tun receiving injected packet", "dataLen", len(packet))
|
||||||
}
|
}
|
||||||
buf := acquireTunBuf(len(packet))
|
t.rxPackets <- packet
|
||||||
copy(buf, packet)
|
|
||||||
t.rxPackets <- buf
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Get will pull an unencrypted ip layer frame from the transmit queue
|
// Get will pull an unencrypted ip layer frame from the transmit queue
|
||||||
@@ -113,49 +105,25 @@ func (t *TestTun) Name() string {
|
|||||||
return t.Device
|
return t.Device
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *TestTun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *TestTun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (t *TestTun) Write(b []byte) (n int, err error) {
|
func (t *TestTun) Write(b []byte) (n int, err error) {
|
||||||
if t.closed.Load() {
|
if t.closed.Load() {
|
||||||
return 0, io.ErrClosedPipe
|
return 0, io.ErrClosedPipe
|
||||||
}
|
}
|
||||||
|
|
||||||
packet := acquireTunBuf(len(b))
|
packet := make([]byte, len(b), len(b))
|
||||||
copy(packet, b)
|
copy(packet, b)
|
||||||
t.TxPackets <- packet
|
t.TxPackets <- packet
|
||||||
return len(b), nil
|
return len(b), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// ReleaseTunBuf returns a slice from TxPackets to the harness freelist, don't use the bytes after the call.
|
|
||||||
// Channel-backed instead of sync.Pool because putting a []byte in a sync.Pool escapes the slice header to heap.
|
|
||||||
func ReleaseTunBuf(b []byte) {
|
|
||||||
if b == nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
select {
|
|
||||||
case tunBufFreelist <- b:
|
|
||||||
default:
|
|
||||||
// Freelist full; drop the buffer for the GC.
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// tunBufFreelist retains the backing arrays for TestTun.Write so steady-state allocation drops to zero once the
|
|
||||||
// freelist has saturated for the current MTU.
|
|
||||||
var tunBufFreelist = make(chan []byte, 64)
|
|
||||||
|
|
||||||
func acquireTunBuf(n int) []byte {
|
|
||||||
var b []byte
|
|
||||||
select {
|
|
||||||
case b = <-tunBufFreelist:
|
|
||||||
default:
|
|
||||||
b = make([]byte, 0, udp.MTU)
|
|
||||||
}
|
|
||||||
if cap(b) < n {
|
|
||||||
b = make([]byte, n)
|
|
||||||
} else {
|
|
||||||
b = b[:n]
|
|
||||||
}
|
|
||||||
return b
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *TestTun) Close() error {
|
func (t *TestTun) Close() error {
|
||||||
if t.closed.CompareAndSwap(false, true) {
|
if t.closed.CompareAndSwap(false, true) {
|
||||||
close(t.rxPackets)
|
close(t.rxPackets)
|
||||||
@@ -164,46 +132,19 @@ func (t *TestTun) Close() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *TestTun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
func (t *TestTun) Read(b []byte) (int, error) {
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.read(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *TestTun) read(b []byte) (int, error) {
|
|
||||||
p, ok := <-t.rxPackets
|
p, ok := <-t.rxPackets
|
||||||
if !ok {
|
if !ok {
|
||||||
return 0, os.ErrClosed
|
return 0, os.ErrClosed
|
||||||
}
|
}
|
||||||
n := len(p)
|
|
||||||
copy(b, p)
|
copy(b, p)
|
||||||
// Send always pushes a freelist-acquired slice, return it once we've copied the bytes into the caller's buffer.
|
return len(p), nil
|
||||||
select {
|
|
||||||
case tunBufFreelist <- p:
|
|
||||||
default:
|
|
||||||
}
|
|
||||||
return n, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *TestTun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *TestTun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *TestTun) SupportsMultiqueue() bool {
|
func (t *TestTun) SupportsMultiqueue() bool {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *TestTun) NewMultiQueueReader() error {
|
func (t *TestTun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented")
|
||||||
}
|
}
|
||||||
|
|||||||
+31
-79
@@ -6,6 +6,7 @@ package overlay
|
|||||||
import (
|
import (
|
||||||
"crypto"
|
"crypto"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
@@ -17,50 +18,26 @@ import (
|
|||||||
|
|
||||||
"github.com/gaissmai/bart"
|
"github.com/gaissmai/bart"
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/util"
|
"github.com/slackhq/nebula/util"
|
||||||
"github.com/slackhq/nebula/wintun"
|
"github.com/slackhq/nebula/wintun"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
"golang.org/x/sys/windows"
|
"golang.org/x/sys/windows"
|
||||||
"golang.zx2c4.com/wireguard/windows/tunnel/winipcfg"
|
"golang.zx2c4.com/wireguard/windows/tunnel/winipcfg"
|
||||||
)
|
)
|
||||||
|
|
||||||
type closer interface {
|
|
||||||
Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
const tunGUIDLabel = "Fixed Nebula Windows GUID v1"
|
const tunGUIDLabel = "Fixed Nebula Windows GUID v1"
|
||||||
|
|
||||||
type winTun struct {
|
type winTun struct {
|
||||||
Device string
|
Device string
|
||||||
vpnNetworks []netip.Prefix
|
vpnNetworks []netip.Prefix
|
||||||
MTU int
|
MTU int
|
||||||
Routes atomic.Pointer[[]Route]
|
Routes atomic.Pointer[[]Route]
|
||||||
routeTree atomic.Pointer[bart.Table[routing.Gateways]]
|
routeTree atomic.Pointer[bart.Table[routing.Gateways]]
|
||||||
guid windows.GUID
|
l *slog.Logger
|
||||||
networkCategory networkCategory
|
|
||||||
setCategory bool
|
|
||||||
bypassWDF bool
|
|
||||||
wdfBypass closer
|
|
||||||
l *slog.Logger
|
|
||||||
|
|
||||||
tun *wintun.NativeTun
|
tun *wintun.NativeTun
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *winTun) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = struct{}{}
|
|
||||||
n, err := t.tun.Read(mem, 0)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (Device, error) {
|
func newTunFromFd(_ *config.C, _ *slog.Logger, _ int, _ []netip.Prefix) (Device, error) {
|
||||||
return nil, fmt.Errorf("newTunFromFd not supported in Windows")
|
return nil, fmt.Errorf("newTunFromFd not supported in Windows")
|
||||||
}
|
}
|
||||||
@@ -77,20 +54,11 @@ func newTun(c *config.C, l *slog.Logger, vpnNetworks []netip.Prefix, _ bool) (*w
|
|||||||
return nil, fmt.Errorf("generate GUID failed: %w", err)
|
return nil, fmt.Errorf("generate GUID failed: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
cat, setCat, err := parseNetworkCategory(c.GetString("tun.network_category", "private"))
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
t := &winTun{
|
t := &winTun{
|
||||||
Device: deviceName,
|
Device: deviceName,
|
||||||
vpnNetworks: vpnNetworks,
|
vpnNetworks: vpnNetworks,
|
||||||
MTU: c.GetInt("tun.mtu", DefaultMTU),
|
MTU: c.GetInt("tun.mtu", DefaultMTU),
|
||||||
guid: *guid,
|
l: l,
|
||||||
networkCategory: cat,
|
|
||||||
setCategory: setCat,
|
|
||||||
bypassWDF: c.GetBool("tun.windows_bypass_wdf", true),
|
|
||||||
l: l,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
err = t.reload(c, true)
|
err = t.reload(c, true)
|
||||||
@@ -174,17 +142,6 @@ func (t *winTun) Activate() error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
if t.setCategory {
|
|
||||||
// The wintun adapter takes a moment to register with the Network List
|
|
||||||
// Manager, so we apply the category in the background and retry until
|
|
||||||
// it shows up.
|
|
||||||
go applyNetworkCategory(t.l, t.guid, t.networkCategory)
|
|
||||||
}
|
|
||||||
|
|
||||||
if t.bypassWDF {
|
|
||||||
t.wdfBypass = installInterfaceBypass(t.l, uint64(t.tun.LUID()))
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -199,8 +156,11 @@ func (t *winTun) addRoutes(logErrors bool) error {
|
|||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
// Add our unsafe route as an on-link route to the nebula tun device.
|
// Add our unsafe route
|
||||||
err := luid.AddRoute(r.Cidr, unspecifiedNextHop(r.Cidr), uint32(r.Metric))
|
// Windows does not support multipath routes natively, so we install only a single route.
|
||||||
|
// This is not a problem as traffic will always be sent to Nebula which handles the multipath routing internally.
|
||||||
|
// In effect this provides multipath routing support to windows supporting loadbalancing and redundancy.
|
||||||
|
err := luid.AddRoute(r.Cidr, r.Via[0].Addr(), uint32(r.Metric))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
retErr := util.NewContextualError("Failed to add route", map[string]any{"route": r}, err)
|
retErr := util.NewContextualError("Failed to add route", map[string]any{"route": r}, err)
|
||||||
if logErrors {
|
if logErrors {
|
||||||
@@ -246,7 +206,7 @@ func (t *winTun) removeRoutes(routes []Route) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// See comment on luid.AddRoute
|
// See comment on luid.AddRoute
|
||||||
err := luid.DeleteRoute(r.Cidr, unspecifiedNextHop(r.Cidr))
|
err := luid.DeleteRoute(r.Cidr, r.Via[0].Addr())
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.l.Error("Failed to remove route", "error", err, "route", r)
|
t.l.Error("Failed to remove route", "error", err, "route", r)
|
||||||
} else {
|
} else {
|
||||||
@@ -269,6 +229,18 @@ func (t *winTun) Name() string {
|
|||||||
return t.Device
|
return t.Device
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *winTun) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *winTun) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *winTun) Read(b []byte) (int, error) {
|
||||||
|
return t.tun.Read(b, 0)
|
||||||
|
}
|
||||||
|
|
||||||
func (t *winTun) Write(b []byte) (int, error) {
|
func (t *winTun) Write(b []byte) (int, error) {
|
||||||
return t.tun.Write(b, 0)
|
return t.tun.Write(b, 0)
|
||||||
}
|
}
|
||||||
@@ -277,16 +249,8 @@ func (t *winTun) SupportsMultiqueue() bool {
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *winTun) NewMultiQueueReader() error {
|
func (t *winTun) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
return fmt.Errorf("TODO: multiqueue not implemented for windows")
|
return nil, fmt.Errorf("TODO: multiqueue not implemented for windows")
|
||||||
}
|
|
||||||
|
|
||||||
func (t *winTun) Readers() []tio.Queue {
|
|
||||||
return []tio.Queue{t}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (t *winTun) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *winTun) Close() error {
|
func (t *winTun) Close() error {
|
||||||
@@ -302,21 +266,9 @@ func (t *winTun) Close() error {
|
|||||||
_ = luid.FlushDNS(windows.AF_INET)
|
_ = luid.FlushDNS(windows.AF_INET)
|
||||||
_ = luid.FlushDNS(windows.AF_INET6)
|
_ = luid.FlushDNS(windows.AF_INET6)
|
||||||
|
|
||||||
if t.wdfBypass != nil {
|
|
||||||
t.wdfBypass.Close()
|
|
||||||
t.wdfBypass = nil
|
|
||||||
}
|
|
||||||
|
|
||||||
return t.tun.Close()
|
return t.tun.Close()
|
||||||
}
|
}
|
||||||
|
|
||||||
func unspecifiedNextHop(p netip.Prefix) netip.Addr {
|
|
||||||
if p.Addr().Is4() {
|
|
||||||
return netip.IPv4Unspecified()
|
|
||||||
}
|
|
||||||
return netip.IPv6Unspecified()
|
|
||||||
}
|
|
||||||
|
|
||||||
func generateGUIDByDeviceName(name string) (*windows.GUID, error) {
|
func generateGUIDByDeviceName(name string) (*windows.GUID, error) {
|
||||||
// GUID is 128 bit
|
// GUID is 128 bit
|
||||||
hash := crypto.MD5.New()
|
hash := crypto.MD5.New()
|
||||||
|
|||||||
+13
-33
@@ -6,9 +6,7 @@ import (
|
|||||||
"net/netip"
|
"net/netip"
|
||||||
|
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/overlay/tio"
|
|
||||||
"github.com/slackhq/nebula/routing"
|
"github.com/slackhq/nebula/routing"
|
||||||
"github.com/slackhq/nebula/wire"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func NewUserDeviceFromConfig(c *config.C, l *slog.Logger, vpnNetworks []netip.Prefix, routines int) (Device, error) {
|
func NewUserDeviceFromConfig(c *config.C, l *slog.Logger, vpnNetworks []netip.Prefix, routines int) (Device, error) {
|
||||||
@@ -25,13 +23,11 @@ func NewUserDevice(vpnNetworks []netip.Prefix) (Device, error) {
|
|||||||
outboundWriter: ow,
|
outboundWriter: ow,
|
||||||
inboundReader: ir,
|
inboundReader: ir,
|
||||||
inboundWriter: iw,
|
inboundWriter: iw,
|
||||||
numReaders: 1,
|
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
type UserDevice struct {
|
type UserDevice struct {
|
||||||
vpnNetworks []netip.Prefix
|
vpnNetworks []netip.Prefix
|
||||||
numReaders int
|
|
||||||
|
|
||||||
outboundReader *io.PipeReader
|
outboundReader *io.PipeReader
|
||||||
outboundWriter *io.PipeWriter
|
outboundWriter *io.PipeWriter
|
||||||
@@ -40,23 +36,6 @@ type UserDevice struct {
|
|||||||
inboundWriter *io.PipeWriter
|
inboundWriter *io.PipeWriter
|
||||||
}
|
}
|
||||||
|
|
||||||
func (d *UserDevice) Capabilities() tio.Capabilities {
|
|
||||||
return tio.Capabilities{}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (d *UserDevice) Read(p []wire.TunPacket, mem []byte) (int, error) {
|
|
||||||
if len(p) == 0 || len(mem) == 0 {
|
|
||||||
return 0, nil //todo should this be an err?
|
|
||||||
}
|
|
||||||
p[0].Meta = wire.GSOInfo{}
|
|
||||||
n, err := d.outboundReader.Read(mem)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
p[0].Bytes = mem[:n]
|
|
||||||
return 1, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (d *UserDevice) Activate() error {
|
func (d *UserDevice) Activate() error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -67,31 +46,32 @@ func (d *UserDevice) RoutesFor(ip netip.Addr) routing.Gateways {
|
|||||||
return routing.Gateways{routing.NewGateway(ip, 1)}
|
return routing.Gateways{routing.NewGateway(ip, 1)}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (d *UserDevice) SupportsPerPeerMTU() bool {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func (d *UserDevice) SetPeerMTU(addr netip.Addr, mtu int) error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (d *UserDevice) SupportsMultiqueue() bool {
|
func (d *UserDevice) SupportsMultiqueue() bool {
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func (d *UserDevice) NewMultiQueueReader() error {
|
func (d *UserDevice) NewMultiQueueReader() (io.ReadWriteCloser, error) {
|
||||||
d.numReaders++
|
return d, nil
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (d *UserDevice) Readers() []tio.Queue {
|
|
||||||
out := make([]tio.Queue, d.numReaders)
|
|
||||||
for i := range d.numReaders {
|
|
||||||
out[i] = d
|
|
||||||
}
|
|
||||||
return out
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (d *UserDevice) Pipe() (*io.PipeReader, *io.PipeWriter) {
|
func (d *UserDevice) Pipe() (*io.PipeReader, *io.PipeWriter) {
|
||||||
return d.inboundReader, d.outboundWriter
|
return d.inboundReader, d.outboundWriter
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (d *UserDevice) Read(p []byte) (n int, err error) {
|
||||||
|
return d.outboundReader.Read(p)
|
||||||
|
}
|
||||||
func (d *UserDevice) Write(p []byte) (n int, err error) {
|
func (d *UserDevice) Write(p []byte) (n int, err error) {
|
||||||
return d.inboundWriter.Write(p)
|
return d.inboundWriter.Write(p)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (d *UserDevice) Close() error {
|
func (d *UserDevice) Close() error {
|
||||||
d.inboundWriter.Close()
|
d.inboundWriter.Close()
|
||||||
d.outboundWriter.Close()
|
d.outboundWriter.Close()
|
||||||
|
|||||||
@@ -99,10 +99,12 @@ func (p *PKI) reloadCerts(c *config.C, initial bool) *util.ContextualError {
|
|||||||
var currentState *CertState
|
var currentState *CertState
|
||||||
if initial {
|
if initial {
|
||||||
cipher = c.GetString("cipher", "aes")
|
cipher = c.GetString("cipher", "aes")
|
||||||
|
//TODO: this sucks and we should make it not a global
|
||||||
switch cipher {
|
switch cipher {
|
||||||
case "aes", "chachapoly":
|
case "aes":
|
||||||
// Each post-handshake CipherState in noiseutil hardcodes its own
|
noiseEndianness = binary.BigEndian
|
||||||
// nonce endianness now, so there's nothing to set up here.
|
case "chachapoly":
|
||||||
|
noiseEndianness = binary.LittleEndian
|
||||||
default:
|
default:
|
||||||
return util.NewContextualError(
|
return util.NewContextualError(
|
||||||
"unknown cipher",
|
"unknown cipher",
|
||||||
|
|||||||
@@ -0,0 +1,623 @@
|
|||||||
|
package nebula
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"encoding/binary"
|
||||||
|
"log/slog"
|
||||||
|
"math/rand/v2"
|
||||||
|
"net/netip"
|
||||||
|
"sync"
|
||||||
|
"sync/atomic"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/slackhq/nebula/config"
|
||||||
|
"github.com/slackhq/nebula/header"
|
||||||
|
"github.com/slackhq/nebula/overlay"
|
||||||
|
)
|
||||||
|
|
||||||
|
// PMTUD PoC: discover the path MTU per-tunnel via authenticated probes that ride
|
||||||
|
// the existing crypto session. We follow RFC 8899 PLPMTUD: a binary search
|
||||||
|
// between a known-good floor and a configured ceiling, with N consecutive probe
|
||||||
|
// losses at a size treated as "doesn't fit." Confirmed PMTU is pushed to the
|
||||||
|
// overlay device, which on Linux installs a per-host route with the discovered
|
||||||
|
// MTU. The kernel then surfaces EMSGSIZE / PTB to apps writing to the tun.
|
||||||
|
//
|
||||||
|
// Probe payload format (request):
|
||||||
|
//
|
||||||
|
// [magic uint32 BE][probeID uint32 BE][padding 0x00...]
|
||||||
|
//
|
||||||
|
// Reply is a small ack with the same magic and probeID and no padding. We do not
|
||||||
|
// verify the reverse-path MTU; only the forward direction matters for the
|
||||||
|
// receiver's MTU on the inside.
|
||||||
|
|
||||||
|
const (
|
||||||
|
pmtudMagic uint32 = 0x504D5544 // 'P' 'M' 'U' 'D'
|
||||||
|
pmtudFloor = 1280 // IPv6 minimum payload, also a safe internet MTU floor
|
||||||
|
|
||||||
|
// pmtudConverged is the bytes-tolerance for stopping the search.
|
||||||
|
pmtudConverged = 8
|
||||||
|
|
||||||
|
// pmtudMaxLoss matches RFC 8899 MAX_PROBES (default 3).
|
||||||
|
pmtudMaxLoss = 3
|
||||||
|
|
||||||
|
// pmtudProbeInterval is the time between probe ticks during the search phase.
|
||||||
|
// Once a peer converges the wheel stops ticking it; re-validation is driven
|
||||||
|
// by connection_manager via MaybeProbeAsTest at its natural test cadence.
|
||||||
|
pmtudProbeInterval = 500 * time.Millisecond
|
||||||
|
|
||||||
|
// pmtudWheelMax is the wheel's maximum supported scheduling duration. We
|
||||||
|
// only ever schedule at pmtudProbeInterval today, but the wheel needs a
|
||||||
|
// max greater than its tick to allocate its slot ring sensibly.
|
||||||
|
pmtudWheelMax = 5 * time.Second
|
||||||
|
|
||||||
|
// pmtudOverheadPessimistic assumes IPv6 underlay + relay framing:
|
||||||
|
// IPv6(40) + UDP(8) + outer nebula(16) + outer AEAD tag(16)
|
||||||
|
// + inner nebula(16) + inner AEAD tag(16) = 112 bytes.
|
||||||
|
// TODO: track underlay address family and per-peer relay state on the HostInfo
|
||||||
|
// so the manager can use the actual overhead for that tunnel and recover the
|
||||||
|
// 32 bytes we pessimistically give up on direct IPv6 paths and the 52 bytes on
|
||||||
|
// direct IPv4 paths.
|
||||||
|
pmtudOverheadPessimistic = 112
|
||||||
|
|
||||||
|
// pmtudUnsupportedAfter is the number of consecutive lost probes (across any
|
||||||
|
// sizes) without ever receiving a reply that we treat as evidence the peer
|
||||||
|
// does not understand the MTUDProbeRequest subtype (i.e. it's running an
|
||||||
|
// older nebula). After this many failures with everReplied=false we mark the
|
||||||
|
// peer pmtud-unsupported and stop scheduling probes. K is small enough that
|
||||||
|
// it fires before the binary search would naturally converge to floor (which
|
||||||
|
// would otherwise be ~30 wasted probes), but large enough to absorb a few
|
||||||
|
// transient probe losses on a path that's just starting to settle.
|
||||||
|
pmtudUnsupportedAfter = 5
|
||||||
|
)
|
||||||
|
|
||||||
|
// pmtudPeer tracks the binary-search state for one tunnel.
|
||||||
|
type pmtudPeer struct {
|
||||||
|
mu sync.Mutex
|
||||||
|
addr netip.Addr
|
||||||
|
localIdx uint32
|
||||||
|
|
||||||
|
// low is the largest outer IP packet size we have a confirmed ack for.
|
||||||
|
// high is the smallest size we believe fails (the search ceiling to start).
|
||||||
|
low, high int
|
||||||
|
|
||||||
|
// inFlightSize is the outer IP packet size of the probe currently awaiting
|
||||||
|
// an ack. 0 means no probe in flight.
|
||||||
|
inFlightSize int
|
||||||
|
// inFlightID matches the probeID echoed in the reply.
|
||||||
|
inFlightID uint32
|
||||||
|
// losses counts consecutive failures at inFlightSize.
|
||||||
|
losses int
|
||||||
|
|
||||||
|
// firstProbe is true until we have sent the first probe of a search. The
|
||||||
|
// first probe targets the ceiling directly (RFC 8899 permits this Search
|
||||||
|
// Algorithm choice); operators who set tun.max_mtu typically have a path
|
||||||
|
// that supports it, so we converge in one probe in the common case.
|
||||||
|
firstProbe bool
|
||||||
|
// everReplied is true once we have ever received any MTUDProbeReply from
|
||||||
|
// this peer. Combined with consecutiveFailures, this lets us detect peers
|
||||||
|
// that don't understand the new subtype and stop probing them.
|
||||||
|
everReplied bool
|
||||||
|
// consecutiveFailures counts probes lost without an intervening reply.
|
||||||
|
// Resets to 0 on any successful reply.
|
||||||
|
consecutiveFailures int
|
||||||
|
// unsupported is set true once we conclude the peer doesn't speak PMTUD.
|
||||||
|
// The manager skips probes for unsupported peers.
|
||||||
|
unsupported bool
|
||||||
|
|
||||||
|
// converged means we have a confirmed PMTU and are in the slow re-validation phase.
|
||||||
|
converged bool
|
||||||
|
// applied is the inner MTU we last pushed to the overlay device (0 if never).
|
||||||
|
applied int
|
||||||
|
}
|
||||||
|
|
||||||
|
func (p *pmtudPeer) overhead() int {
|
||||||
|
// TODO: branch on actual underlay family + relay state for this peer.
|
||||||
|
return pmtudOverheadPessimistic
|
||||||
|
}
|
||||||
|
|
||||||
|
func (p *pmtudPeer) midpoint() int {
|
||||||
|
return (p.low + p.high) / 2
|
||||||
|
}
|
||||||
|
|
||||||
|
type pmtudManager struct {
|
||||||
|
intf *Interface
|
||||||
|
device overlay.Device
|
||||||
|
|
||||||
|
// peers is keyed by HostInfo.localIndexId.
|
||||||
|
peers sync.Map // map[uint32]*pmtudPeer
|
||||||
|
|
||||||
|
wheel *LockingTimerWheel[uint32]
|
||||||
|
|
||||||
|
// floor is the always-safe inner MTU (= tun.mtu). Per-peer routes start here
|
||||||
|
// on tunnel-up so unprobed traffic is always small enough to fit. Stored as
|
||||||
|
// atomic int64 so reload can update it without coordinating with the readers
|
||||||
|
// in tick/HandleReply/OnTunnelUp.
|
||||||
|
floor atomic.Int64
|
||||||
|
// ceiling is the search ceiling expressed as an outer IP packet size, derived
|
||||||
|
// from tun.max_mtu (which is the kernel's device MTU on the tun) plus our
|
||||||
|
// pessimistic overhead. PMTUD will not probe larger than this.
|
||||||
|
ceiling atomic.Int64
|
||||||
|
|
||||||
|
enabled atomic.Bool
|
||||||
|
|
||||||
|
l *slog.Logger
|
||||||
|
}
|
||||||
|
|
||||||
|
func newPMTUDManagerFromConfig(l *slog.Logger, c *config.C, device overlay.Device) *pmtudManager {
|
||||||
|
m := &pmtudManager{
|
||||||
|
device: device,
|
||||||
|
wheel: NewLockingTimerWheel[uint32](pmtudProbeInterval, pmtudWheelMax),
|
||||||
|
l: l,
|
||||||
|
}
|
||||||
|
c.RegisterReloadCallback(func(c *config.C) { m.reload(c, false) })
|
||||||
|
m.reload(c, true)
|
||||||
|
return m
|
||||||
|
}
|
||||||
|
|
||||||
|
// reload applies tun.mtu / tun.max_mtu changes to the manager. On the initial
|
||||||
|
// call (during construction) it just snapshots state; on a live reload it also
|
||||||
|
// transitions in-flight peers to match the new bounds: clearing per-peer routes
|
||||||
|
// when newly disabled, seeding peers from the hostmap and flipping DF on
|
||||||
|
// outside sockets when newly enabled, and rebounding existing searches in
|
||||||
|
// place when only the ceiling moved.
|
||||||
|
func (m *pmtudManager) reload(c *config.C, initial bool) {
|
||||||
|
if !initial && !c.HasChanged("tun.mtu") && !c.HasChanged("tun.max_mtu") {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
floor := c.GetInt("tun.mtu", overlay.DefaultMTU)
|
||||||
|
maxMTU := c.GetInt("tun.max_mtu", 0)
|
||||||
|
|
||||||
|
enable := maxMTU > floor && m.device.SupportsPerPeerMTU()
|
||||||
|
var ceiling int
|
||||||
|
if enable {
|
||||||
|
ceiling = maxMTU + pmtudOverheadPessimistic
|
||||||
|
}
|
||||||
|
|
||||||
|
if initial {
|
||||||
|
m.floor.Store(int64(floor))
|
||||||
|
m.ceiling.Store(int64(ceiling))
|
||||||
|
m.enabled.Store(enable)
|
||||||
|
switch {
|
||||||
|
case enable:
|
||||||
|
m.l.Info("pmtud enabled", "floor", floor, "ceiling", ceiling, "tun.max_mtu", maxMTU)
|
||||||
|
case maxMTU > floor:
|
||||||
|
m.l.Warn("pmtud disabled: this platform does not yet support per-peer MTU routes",
|
||||||
|
"tun.max_mtu", maxMTU)
|
||||||
|
}
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
wasEnabled := m.enabled.Load()
|
||||||
|
m.floor.Store(int64(floor))
|
||||||
|
m.ceiling.Store(int64(ceiling))
|
||||||
|
m.enabled.Store(enable)
|
||||||
|
|
||||||
|
switch {
|
||||||
|
case wasEnabled && !enable:
|
||||||
|
m.disableLive(floor, maxMTU)
|
||||||
|
case !wasEnabled && enable:
|
||||||
|
m.enableLive(floor, ceiling, maxMTU)
|
||||||
|
case wasEnabled && enable:
|
||||||
|
m.reboundLive(floor, ceiling, maxMTU)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// disableLive clears per-peer routes and drops all peer state. We do not
|
||||||
|
// disable DF on the outside sockets; once on, it stays on for the life of the
|
||||||
|
// process. Operators flipping pmtud off live get correct routing behavior; if
|
||||||
|
// they want the historical no-DF behavior back they need to restart.
|
||||||
|
func (m *pmtudManager) disableLive(floor, maxMTU int) {
|
||||||
|
m.peers.Range(func(k, v any) bool {
|
||||||
|
p := v.(*pmtudPeer)
|
||||||
|
p.mu.Lock()
|
||||||
|
applied := p.applied
|
||||||
|
addr := p.addr
|
||||||
|
p.applied = 0
|
||||||
|
p.mu.Unlock()
|
||||||
|
if applied != 0 {
|
||||||
|
if err := m.device.SetPeerMTU(addr, 0); err != nil {
|
||||||
|
m.l.Warn("pmtud: failed to clear per-peer mtu on disable", "addr", addr, "error", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
m.peers.Delete(k)
|
||||||
|
return true
|
||||||
|
})
|
||||||
|
m.l.Info("pmtud disabled (tun.max_mtu <= tun.mtu)", "tun.mtu", floor, "tun.max_mtu", maxMTU)
|
||||||
|
}
|
||||||
|
|
||||||
|
// enableLive flips DF on every outside socket. We don't pre-seed existing
|
||||||
|
// tunnels here; connection_manager's normal test cadence will eventually call
|
||||||
|
// MaybeProbeAsTest for each peer, which seeds on miss and lets the wheel pick
|
||||||
|
// up the search from there. New tunnels established after this point still
|
||||||
|
// take the OnTunnelUp fast path.
|
||||||
|
func (m *pmtudManager) enableLive(floor, ceiling, maxMTU int) {
|
||||||
|
m.enableDF()
|
||||||
|
m.l.Info("pmtud enabled", "floor", floor, "ceiling", ceiling, "tun.max_mtu", maxMTU)
|
||||||
|
}
|
||||||
|
|
||||||
|
// reboundLive resets each peer's search state to the new bounds. Peers whose
|
||||||
|
// confirmed PMTU still fits under the new ceiling keep their applied route in
|
||||||
|
// place during the new search; peers whose confirmed PMTU exceeds the new
|
||||||
|
// ceiling get cleared back to floor and re-search from scratch. The unsupported
|
||||||
|
// flag is preserved because peer software version doesn't change on reload.
|
||||||
|
func (m *pmtudManager) reboundLive(floor, ceiling, maxMTU int) {
|
||||||
|
overhead := pmtudOverheadPessimistic
|
||||||
|
m.peers.Range(func(k, v any) bool {
|
||||||
|
p := v.(*pmtudPeer)
|
||||||
|
p.mu.Lock()
|
||||||
|
if p.applied > 0 && p.applied+overhead > ceiling {
|
||||||
|
if err := m.device.SetPeerMTU(p.addr, 0); err != nil {
|
||||||
|
m.l.Warn("pmtud: failed to clear per-peer mtu on rebound", "addr", p.addr, "error", err)
|
||||||
|
} else {
|
||||||
|
p.applied = 0
|
||||||
|
}
|
||||||
|
}
|
||||||
|
p.low = floor + overhead
|
||||||
|
p.high = ceiling
|
||||||
|
p.inFlightSize = 0
|
||||||
|
p.inFlightID = 0
|
||||||
|
p.losses = 0
|
||||||
|
p.firstProbe = !p.unsupported
|
||||||
|
p.converged = false
|
||||||
|
idx := p.localIdx
|
||||||
|
unsupported := p.unsupported
|
||||||
|
p.mu.Unlock()
|
||||||
|
if !unsupported {
|
||||||
|
m.wheel.Add(idx, pmtudProbeInterval)
|
||||||
|
}
|
||||||
|
return true
|
||||||
|
})
|
||||||
|
m.l.Info("pmtud reloaded", "floor", floor, "ceiling", ceiling, "tun.max_mtu", maxMTU)
|
||||||
|
}
|
||||||
|
|
||||||
|
// enableDF asks every outside socket to set the don't-fragment bit on outbound
|
||||||
|
// packets. Idempotent: safe to call from both Start (initial enable) and from a
|
||||||
|
// live reload that flips pmtud on.
|
||||||
|
func (m *pmtudManager) enableDF() {
|
||||||
|
for i, w := range m.intf.writers {
|
||||||
|
if err := w.EnablePathMTUDiscovery(); err != nil {
|
||||||
|
m.l.Warn("pmtud: failed to enable path mtu discovery on outside socket; pmtud will not work correctly",
|
||||||
|
"writer", i, "error", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Start runs the probe scheduler until ctx is done. The loop runs even when PMTUD
|
||||||
|
// is disabled at startup so a hot reload can turn it on without restarting nebula.
|
||||||
|
//
|
||||||
|
// When PMTUD is enabled at startup we ask each outside socket to enable
|
||||||
|
// path-MTU discovery (DF on every send). This is intentionally gated on the
|
||||||
|
// feature being on so that operators who haven't opted in keep the historical
|
||||||
|
// behavior where the kernel may fragment outbound nebula UDP packets. A live
|
||||||
|
// reload from disabled to enabled will also flip DF on via enableLive; the
|
||||||
|
// reverse direction does not turn DF off, so flipping pmtud back off live
|
||||||
|
// keeps DF on until restart.
|
||||||
|
func (m *pmtudManager) Start(ctx context.Context) {
|
||||||
|
if m.enabled.Load() {
|
||||||
|
m.enableDF()
|
||||||
|
}
|
||||||
|
|
||||||
|
ticker := time.NewTicker(m.wheel.t.tickDuration)
|
||||||
|
defer ticker.Stop()
|
||||||
|
|
||||||
|
for {
|
||||||
|
select {
|
||||||
|
case <-ctx.Done():
|
||||||
|
return
|
||||||
|
case now := <-ticker.C:
|
||||||
|
m.wheel.Advance(now)
|
||||||
|
for {
|
||||||
|
idx, has := m.wheel.Purge()
|
||||||
|
if !has {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
m.tick(idx)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// OnTunnelUp is called when a HostInfo becomes traffic-watched. The kernel
|
||||||
|
// already routes packets to this peer through the per-vpn-network route (mtu =
|
||||||
|
// tun.mtu), so the floor is in effect implicitly. We just kick off the search
|
||||||
|
// here; HandleReply will install a per-host /32 (or /128) route once a larger
|
||||||
|
// size is confirmed.
|
||||||
|
func (m *pmtudManager) OnTunnelUp(hi *HostInfo) {
|
||||||
|
if !m.enabled.Load() {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
m.seedPeer(hi)
|
||||||
|
}
|
||||||
|
|
||||||
|
// seedPeer is the shared body of OnTunnelUp and the live-reload enable path.
|
||||||
|
// LoadOrStore protects against double-seeding the same localIndexId from a
|
||||||
|
// race between OnTunnelUp and a reload-driven hostmap walk.
|
||||||
|
func (m *pmtudManager) seedPeer(hi *HostInfo) {
|
||||||
|
if hi == nil || len(hi.vpnAddrs) == 0 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
floor := int(m.floor.Load())
|
||||||
|
ceiling := int(m.ceiling.Load())
|
||||||
|
p := &pmtudPeer{
|
||||||
|
addr: hi.vpnAddrs[0],
|
||||||
|
localIdx: hi.localIndexId,
|
||||||
|
low: floor + pmtudOverheadPessimistic,
|
||||||
|
high: ceiling,
|
||||||
|
firstProbe: true,
|
||||||
|
}
|
||||||
|
if _, loaded := m.peers.LoadOrStore(hi.localIndexId, p); loaded {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
m.wheel.Add(hi.localIndexId, pmtudProbeInterval)
|
||||||
|
}
|
||||||
|
|
||||||
|
// OnTunnelDown is called when a HostInfo is being torn down. Removes any per-host
|
||||||
|
// MTU override so the device default applies again.
|
||||||
|
func (m *pmtudManager) OnTunnelDown(hi *HostInfo) {
|
||||||
|
if hi == nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
v, ok := m.peers.LoadAndDelete(hi.localIndexId)
|
||||||
|
if !ok {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
p := v.(*pmtudPeer)
|
||||||
|
p.mu.Lock()
|
||||||
|
applied := p.applied
|
||||||
|
addr := p.addr
|
||||||
|
p.applied = 0
|
||||||
|
p.mu.Unlock()
|
||||||
|
if applied != 0 {
|
||||||
|
if err := m.device.SetPeerMTU(addr, 0); err != nil {
|
||||||
|
m.l.Warn("pmtud: failed to clear per-peer mtu", "addr", addr, "error", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// OnRoam is called when a HostInfo's remote underlay address changes. The path
|
||||||
|
// MTU may now be different; drop the per-host route so the kernel falls back to
|
||||||
|
// the per-vpn-network route (mtu = tun.mtu floor), then restart the search.
|
||||||
|
// We do not reset the unsupported flag: peer software version doesn't change on
|
||||||
|
// roam, so once we've decided a peer doesn't speak PMTUD we stay decided.
|
||||||
|
func (m *pmtudManager) OnRoam(hi *HostInfo) {
|
||||||
|
if !m.enabled.Load() || hi == nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
v, ok := m.peers.Load(hi.localIndexId)
|
||||||
|
if !ok {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
p := v.(*pmtudPeer)
|
||||||
|
p.mu.Lock()
|
||||||
|
if p.unsupported {
|
||||||
|
p.mu.Unlock()
|
||||||
|
return
|
||||||
|
}
|
||||||
|
p.low = int(m.floor.Load()) + pmtudOverheadPessimistic
|
||||||
|
p.high = int(m.ceiling.Load())
|
||||||
|
p.inFlightSize = 0
|
||||||
|
p.inFlightID = 0
|
||||||
|
p.losses = 0
|
||||||
|
p.consecutiveFailures = 0
|
||||||
|
p.firstProbe = true
|
||||||
|
p.converged = false
|
||||||
|
if p.applied != 0 {
|
||||||
|
if err := m.device.SetPeerMTU(p.addr, 0); err != nil {
|
||||||
|
m.l.Warn("pmtud: failed to clear per-peer mtu on roam", "addr", p.addr, "error", err)
|
||||||
|
} else {
|
||||||
|
p.applied = 0
|
||||||
|
}
|
||||||
|
}
|
||||||
|
p.mu.Unlock()
|
||||||
|
m.wheel.Add(hi.localIndexId, pmtudProbeInterval)
|
||||||
|
}
|
||||||
|
|
||||||
|
// MaybeProbeAsTest is called by connection_manager when it would otherwise send
|
||||||
|
// a TestRequest because a tunnel has gone silent. If we have a confirmed PMTU
|
||||||
|
// for this peer that's larger than the floor, we send a probe at that size
|
||||||
|
// instead. The reply confirms both liveness (consumed by connection_manager via
|
||||||
|
// the existing inbound traffic accounting fallthrough in outside.go) and that
|
||||||
|
// the confirmed PMTU still fits (consumed by HandleReply here). One synthetic
|
||||||
|
// packet does the work of two.
|
||||||
|
//
|
||||||
|
// Returns true if a probe was sent. False means the caller should send a
|
||||||
|
// regular TestRequest at the floor.
|
||||||
|
//
|
||||||
|
// On probe failure, connection_manager's existing pendingDeletion timeout will
|
||||||
|
// tear the tunnel down. Heavy hammer, but correct: a re-handshake re-runs PMTUD
|
||||||
|
// discovery against the now-shrunken path. A future EMSGSIZE-capture followup
|
||||||
|
// can replace this with a soft-drop-and-research flow.
|
||||||
|
func (m *pmtudManager) MaybeProbeAsTest(hi *HostInfo) bool {
|
||||||
|
if !m.enabled.Load() || hi == nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
v, ok := m.peers.Load(hi.localIndexId)
|
||||||
|
if !ok {
|
||||||
|
// Tunnel pre-dates the manager being aware of it (e.g. pmtud was just
|
||||||
|
// enabled live, or AddTrafficWatch fired before this call). Seed the
|
||||||
|
// peer so the wheel picks up the search; let connection_manager send
|
||||||
|
// its regular TestRequest this cycle.
|
||||||
|
m.seedPeer(hi)
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
p := v.(*pmtudPeer)
|
||||||
|
p.mu.Lock()
|
||||||
|
if p.unsupported || p.applied == 0 {
|
||||||
|
p.mu.Unlock()
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
overhead := p.overhead()
|
||||||
|
size := p.applied + overhead
|
||||||
|
id := rand.Uint32()
|
||||||
|
p.inFlightSize = size
|
||||||
|
p.inFlightID = id
|
||||||
|
p.mu.Unlock()
|
||||||
|
|
||||||
|
m.sendProbe(hi, size, id, overhead)
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
|
// HandleReply consumes an MTUDProbeReply payload from the receive path.
|
||||||
|
func (m *pmtudManager) HandleReply(localIdx uint32, payload []byte) {
|
||||||
|
if !m.enabled.Load() {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if len(payload) < 8 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if binary.BigEndian.Uint32(payload[0:4]) != pmtudMagic {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
id := binary.BigEndian.Uint32(payload[4:8])
|
||||||
|
|
||||||
|
v, ok := m.peers.Load(localIdx)
|
||||||
|
if !ok {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
p := v.(*pmtudPeer)
|
||||||
|
p.mu.Lock()
|
||||||
|
defer p.mu.Unlock()
|
||||||
|
|
||||||
|
if p.inFlightSize == 0 || p.inFlightID != id {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
confirmed := p.inFlightSize
|
||||||
|
p.low = confirmed
|
||||||
|
p.inFlightSize = 0
|
||||||
|
p.losses = 0
|
||||||
|
p.everReplied = true
|
||||||
|
p.consecutiveFailures = 0
|
||||||
|
|
||||||
|
innerMTU := confirmed - p.overhead()
|
||||||
|
// Only install a /32 override when it would actually raise the MTU above the
|
||||||
|
// per-vpn-network floor route. If the discovered MTU is <= floor, the /24
|
||||||
|
// already covers it; installing a /32 at floor would just create roam churn.
|
||||||
|
if innerMTU > int(m.floor.Load()) && p.applied != innerMTU {
|
||||||
|
if err := m.device.SetPeerMTU(p.addr, innerMTU); err != nil {
|
||||||
|
m.l.Warn("pmtud: failed to apply per-peer mtu", "addr", p.addr, "innerMTU", innerMTU, "error", err)
|
||||||
|
} else {
|
||||||
|
m.l.Info("pmtud probe confirmed",
|
||||||
|
"addr", p.addr,
|
||||||
|
"outerMTU", confirmed,
|
||||||
|
"innerMTU", innerMTU,
|
||||||
|
"low", p.low,
|
||||||
|
"high", p.high,
|
||||||
|
)
|
||||||
|
p.applied = innerMTU
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if p.high-p.low <= pmtudConverged {
|
||||||
|
p.converged = true
|
||||||
|
} else {
|
||||||
|
p.converged = false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// tick handles one wheel firing for a single peer.
|
||||||
|
func (m *pmtudManager) tick(localIdx uint32) {
|
||||||
|
v, ok := m.peers.Load(localIdx)
|
||||||
|
if !ok {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
p := v.(*pmtudPeer)
|
||||||
|
p.mu.Lock()
|
||||||
|
|
||||||
|
if p.unsupported {
|
||||||
|
p.mu.Unlock()
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// If a probe was outstanding, this tick is the loss timeout.
|
||||||
|
if p.inFlightSize != 0 {
|
||||||
|
p.losses++
|
||||||
|
p.consecutiveFailures++
|
||||||
|
if p.losses >= pmtudMaxLoss {
|
||||||
|
p.high = p.inFlightSize
|
||||||
|
p.inFlightSize = 0
|
||||||
|
p.losses = 0
|
||||||
|
if p.high-p.low <= pmtudConverged {
|
||||||
|
p.converged = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// If we've never gotten a reply from this peer and we've burned through our
|
||||||
|
// failure budget, conclude the peer doesn't understand the MTUDProbeRequest
|
||||||
|
// subtype and stop scheduling probes for it.
|
||||||
|
if !p.everReplied && p.consecutiveFailures >= pmtudUnsupportedAfter {
|
||||||
|
p.unsupported = true
|
||||||
|
addr := p.addr
|
||||||
|
p.mu.Unlock()
|
||||||
|
m.l.Info("pmtud: peer not responding to probes, marking unsupported",
|
||||||
|
"addr", addr, "failures", pmtudUnsupportedAfter)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
hi := m.intf.hostMap.QueryIndex(localIdx)
|
||||||
|
if hi == nil {
|
||||||
|
p.mu.Unlock()
|
||||||
|
m.peers.Delete(localIdx)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// Once a peer converges, the wheel stops scheduling for it. Re-validation
|
||||||
|
// (and the resulting black hole detection) is driven by connection_manager
|
||||||
|
// via MaybeProbeAsTest at its natural test cadence, so a converged peer
|
||||||
|
// has nothing for the wheel to do until OnRoam or a tunnel down/up cycle
|
||||||
|
// triggers a fresh search.
|
||||||
|
if p.converged {
|
||||||
|
p.mu.Unlock()
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
ceiling := int(m.ceiling.Load())
|
||||||
|
var size int
|
||||||
|
switch {
|
||||||
|
case p.firstProbe:
|
||||||
|
// Probe the ceiling directly. If the path supports it (the common case
|
||||||
|
// when an operator has explicitly configured tun.max_mtu), we converge
|
||||||
|
// in one round trip. If it fails, the standard binary search resumes
|
||||||
|
// on the next tick from the (low, ceiling) bounds.
|
||||||
|
size = ceiling
|
||||||
|
p.firstProbe = false
|
||||||
|
case p.losses > 0 && p.inFlightSize != 0:
|
||||||
|
size = p.inFlightSize
|
||||||
|
default:
|
||||||
|
size = p.midpoint()
|
||||||
|
}
|
||||||
|
if size < pmtudFloor {
|
||||||
|
size = pmtudFloor
|
||||||
|
}
|
||||||
|
if size > ceiling {
|
||||||
|
size = ceiling
|
||||||
|
}
|
||||||
|
|
||||||
|
id := rand.Uint32()
|
||||||
|
p.inFlightSize = size
|
||||||
|
p.inFlightID = id
|
||||||
|
overhead := p.overhead()
|
||||||
|
p.mu.Unlock()
|
||||||
|
|
||||||
|
m.sendProbe(hi, size, id, overhead)
|
||||||
|
m.wheel.Add(localIdx, pmtudProbeInterval)
|
||||||
|
}
|
||||||
|
|
||||||
|
// sendProbe builds an MTUDProbeRequest payload that will produce an outer IP
|
||||||
|
// packet of approximately `outerSize` bytes, then sends it.
|
||||||
|
func (m *pmtudManager) sendProbe(hi *HostInfo, outerSize int, id uint32, overhead int) {
|
||||||
|
payloadLen := outerSize - overhead
|
||||||
|
if payloadLen < 8 {
|
||||||
|
payloadLen = 8
|
||||||
|
}
|
||||||
|
p := make([]byte, payloadLen)
|
||||||
|
binary.BigEndian.PutUint32(p[0:4], pmtudMagic)
|
||||||
|
binary.BigEndian.PutUint32(p[4:8], id)
|
||||||
|
// remaining bytes are zero-padding
|
||||||
|
|
||||||
|
nb := make([]byte, 12)
|
||||||
|
out := make([]byte, outerSize+128) // headroom for header/tag/relay framing
|
||||||
|
m.intf.SendMessageToHostInfo(header.Test, header.MTUDProbeRequest, hi, p, nb, out)
|
||||||
|
}
|
||||||
@@ -1,70 +1,24 @@
|
|||||||
package nebula
|
package nebula
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/rcrowley/go-metrics"
|
|
||||||
"github.com/slackhq/nebula/config"
|
"github.com/slackhq/nebula/config"
|
||||||
"github.com/slackhq/nebula/header"
|
|
||||||
"github.com/slackhq/nebula/udp"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// holepunchQueueSize buffers the channel that pending holepunchJobs land on after their delay timer fires.
|
|
||||||
const holepunchQueueSize = 64
|
|
||||||
|
|
||||||
// holepunchJob is one scheduled item delivered to the worker goroutine.
|
|
||||||
// - target valid -> send a UDP punch to target. vpnAddr, if set, is the peer's vpn addr carried for log context.
|
|
||||||
// - target invalid, vpnAddr valid -> send an encrypted test packet to vpnAddr (a "punchback").
|
|
||||||
type holepunchJob struct {
|
|
||||||
target netip.AddrPort
|
|
||||||
vpnAddr netip.Addr
|
|
||||||
}
|
|
||||||
|
|
||||||
// lighthouseChecker is the slice of LightHouse that Punchy actually needs.
|
|
||||||
// Defined here so Punchy doesn't take a *LightHouse dependency (LightHouse
|
|
||||||
// already holds a *Punchy, and the bidirectional pointer reference is awkward
|
|
||||||
// even within the same package). Tests can also substitute a fake.
|
|
||||||
type lighthouseChecker interface {
|
|
||||||
IsAnyLighthouseAddr(vpnAddrs []netip.Addr) bool
|
|
||||||
}
|
|
||||||
|
|
||||||
type Punchy struct {
|
type Punchy struct {
|
||||||
punch atomic.Bool
|
punch atomic.Bool
|
||||||
respond atomic.Bool
|
respond atomic.Bool
|
||||||
delay atomic.Int64
|
delay atomic.Int64
|
||||||
respondDelay atomic.Int64
|
respondDelay atomic.Int64
|
||||||
punchEverything atomic.Bool
|
punchEverything atomic.Bool
|
||||||
|
l *slog.Logger
|
||||||
sched *Scheduler[holepunchJob]
|
|
||||||
punchConn udp.Conn
|
|
||||||
metricHolepunchTx metrics.Counter
|
|
||||||
metricPunchyTx metrics.Counter
|
|
||||||
|
|
||||||
ctx context.Context
|
|
||||||
ifce EncWriter
|
|
||||||
hm *HostMap
|
|
||||||
lh lighthouseChecker
|
|
||||||
|
|
||||||
l *slog.Logger
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewPunchyFromConfig(l *slog.Logger, c *config.C, punchConn udp.Conn) *Punchy {
|
func NewPunchyFromConfig(l *slog.Logger, c *config.C) *Punchy {
|
||||||
p := &Punchy{
|
p := &Punchy{l: l}
|
||||||
l: l,
|
|
||||||
punchConn: punchConn,
|
|
||||||
sched: NewScheduler[holepunchJob](holepunchQueueSize),
|
|
||||||
metricPunchyTx: metrics.GetOrRegisterCounter("messages.tx.punchy", nil),
|
|
||||||
}
|
|
||||||
|
|
||||||
if c.GetBool("stats.lighthouse_metrics", false) {
|
|
||||||
p.metricHolepunchTx = metrics.GetOrRegisterCounter("messages.tx.holepunch", nil)
|
|
||||||
} else {
|
|
||||||
p.metricHolepunchTx = metrics.NilCounter{}
|
|
||||||
}
|
|
||||||
|
|
||||||
p.reload(c, true)
|
p.reload(c, true)
|
||||||
c.RegisterReloadCallback(func(c *config.C) {
|
c.RegisterReloadCallback(func(c *config.C) {
|
||||||
@@ -75,7 +29,7 @@ func NewPunchyFromConfig(l *slog.Logger, c *config.C, punchConn udp.Conn) *Punch
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (p *Punchy) reload(c *config.C, initial bool) {
|
func (p *Punchy) reload(c *config.C, initial bool) {
|
||||||
if initial || c.HasChanged("punchy.punch") || c.HasChanged("punchy") {
|
if initial {
|
||||||
var yes bool
|
var yes bool
|
||||||
if c.IsSet("punchy.punch") {
|
if c.IsSet("punchy.punch") {
|
||||||
yes = c.GetBool("punchy.punch", false)
|
yes = c.GetBool("punchy.punch", false)
|
||||||
@@ -84,15 +38,16 @@ func (p *Punchy) reload(c *config.C, initial bool) {
|
|||||||
yes = c.GetBool("punchy", false)
|
yes = c.GetBool("punchy", false)
|
||||||
}
|
}
|
||||||
|
|
||||||
old := p.punch.Swap(yes)
|
p.punch.Store(yes)
|
||||||
switch {
|
if yes {
|
||||||
case initial && yes:
|
|
||||||
p.l.Info("punchy enabled")
|
p.l.Info("punchy enabled")
|
||||||
case initial:
|
} else {
|
||||||
p.l.Info("punchy disabled")
|
p.l.Info("punchy disabled")
|
||||||
case old != yes:
|
|
||||||
p.l.Info("punchy.punch changed", "punch", yes)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
} else if c.HasChanged("punchy.punch") || c.HasChanged("punchy") {
|
||||||
|
//TODO: it should be relatively easy to support this, just need to be able to cancel the goroutine and boot it up from here
|
||||||
|
p.l.Warn("Changing punchy.punch with reload is not supported, ignoring.")
|
||||||
}
|
}
|
||||||
|
|
||||||
if initial || c.HasChanged("punchy.respond") || c.HasChanged("punch_back") {
|
if initial || c.HasChanged("punchy.respond") || c.HasChanged("punch_back") {
|
||||||
@@ -104,132 +59,52 @@ func (p *Punchy) reload(c *config.C, initial bool) {
|
|||||||
yes = c.GetBool("punch_back", false)
|
yes = c.GetBool("punch_back", false)
|
||||||
}
|
}
|
||||||
|
|
||||||
old := p.respond.Swap(yes)
|
p.respond.Store(yes)
|
||||||
if !initial && old != yes {
|
|
||||||
p.l.Info("punchy.respond changed", "respond", yes)
|
if !initial {
|
||||||
|
p.l.Info("punchy.respond changed", "respond", p.GetRespond())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
//NOTE: this will not apply to any in progress operations, only the next one
|
//NOTE: this will not apply to any in progress operations, only the next one
|
||||||
if initial || c.HasChanged("punchy.delay") {
|
if initial || c.HasChanged("punchy.delay") {
|
||||||
newDelay := int64(c.GetDuration("punchy.delay", time.Second))
|
p.delay.Store((int64)(c.GetDuration("punchy.delay", time.Second)))
|
||||||
old := p.delay.Swap(newDelay)
|
if !initial {
|
||||||
if !initial && old != newDelay {
|
p.l.Info("punchy.delay changed", "delay", p.GetDelay())
|
||||||
p.l.Info("punchy.delay changed", "delay", time.Duration(newDelay))
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if initial || c.HasChanged("punchy.target_all_remotes") {
|
if initial || c.HasChanged("punchy.target_all_remotes") {
|
||||||
yes := c.GetBool("punchy.target_all_remotes", false)
|
p.punchEverything.Store(c.GetBool("punchy.target_all_remotes", false))
|
||||||
old := p.punchEverything.Swap(yes)
|
if !initial {
|
||||||
if !initial && old != yes {
|
p.l.Info("punchy.target_all_remotes changed", "target_all_remotes", p.GetTargetEverything())
|
||||||
p.l.Info("punchy.target_all_remotes changed", "target_all_remotes", yes)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if initial || c.HasChanged("punchy.respond_delay") {
|
if initial || c.HasChanged("punchy.respond_delay") {
|
||||||
newDelay := int64(c.GetDuration("punchy.respond_delay", 5*time.Second))
|
p.respondDelay.Store((int64)(c.GetDuration("punchy.respond_delay", 5*time.Second)))
|
||||||
old := p.respondDelay.Swap(newDelay)
|
if !initial {
|
||||||
if !initial && old != newDelay {
|
p.l.Info("punchy.respond_delay changed", "respond_delay", p.GetRespondDelay())
|
||||||
p.l.Info("punchy.respond_delay changed", "respond_delay", time.Duration(newDelay))
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Schedule queues a punch packet to target, to be sent after the configured delay.
|
func (p *Punchy) GetPunch() bool {
|
||||||
// vpnAddr is the peer's vpn addr, used for log context when the packet actually fires.
|
return p.punch.Load()
|
||||||
// No-op if target is not a valid AddrPort or if Start has not yet been called. Safe to call from any goroutine.
|
|
||||||
func (p *Punchy) Schedule(target netip.AddrPort, vpnAddr netip.Addr) {
|
|
||||||
if !target.IsValid() || p.ctx == nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
p.scheduleJob(holepunchJob{target: target, vpnAddr: vpnAddr}, time.Duration(p.delay.Load()))
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// ScheduleRespond queues a punchback test packet to vpnAddr after the configured respond delay,
|
func (p *Punchy) GetRespond() bool {
|
||||||
// gated on punchy.respond. No-op when respond is disabled or before Start has been called.
|
return p.respond.Load()
|
||||||
func (p *Punchy) ScheduleRespond(vpnAddr netip.Addr) {
|
|
||||||
if !p.respond.Load() || p.ctx == nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
p.scheduleJob(holepunchJob{vpnAddr: vpnAddr}, time.Duration(p.respondDelay.Load()))
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// scheduleJob delegates to the pooled Scheduler.
|
func (p *Punchy) GetDelay() time.Duration {
|
||||||
// The callback observes p.ctx so a job that becomes due after Stop is dropped instead of queued.
|
return (time.Duration)(p.delay.Load())
|
||||||
func (p *Punchy) scheduleJob(job holepunchJob, delay time.Duration) {
|
|
||||||
p.sched.Schedule(p.ctx, job, delay)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// SendPunch sends an immediate keepalive punch for an idle hostinfo.
|
func (p *Punchy) GetRespondDelay() time.Duration {
|
||||||
// The configured punchy.target_all_remotes mode picks the targets. Gated on punchy.punch and the lighthouse-skip rule
|
return (time.Duration)(p.respondDelay.Load())
|
||||||
// (lighthouses don't get keepalive punches because the regular update interval keeps their NAT state warm).
|
|
||||||
func (p *Punchy) SendPunch(hostinfo *HostInfo) {
|
|
||||||
if !p.punch.Load() {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if p.lh.IsAnyLighthouseAddr(hostinfo.vpnAddrs) {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if p.punchEverything.Load() {
|
|
||||||
p.sendPunchToAllRemotes(hostinfo)
|
|
||||||
} else if hostinfo.remote.IsValid() {
|
|
||||||
p.metricPunchyTx.Inc(1)
|
|
||||||
p.punchConn.WriteTo([]byte{1}, hostinfo.remote)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// SendPunchToAll punches every known remote for hostinfo, but only when punchy.target_all_remotes is enabled.
|
func (p *Punchy) GetTargetEverything() bool {
|
||||||
// The connection manager calls this during outbound-only traffic: the outbound traffic itself keeps the primary's
|
return p.punchEverything.Load()
|
||||||
// NAT state warm, but non-primary remotes need separate refresh, so we fan out to all of them (the redundant
|
|
||||||
// primary punch is harmless). Gated on punchy.punch and the lighthouse-skip rule.
|
|
||||||
func (p *Punchy) SendPunchToAll(hostinfo *HostInfo) {
|
|
||||||
if !p.punchEverything.Load() {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if !p.punch.Load() {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if p.lh.IsAnyLighthouseAddr(hostinfo.vpnAddrs) {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
p.sendPunchToAllRemotes(hostinfo)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (p *Punchy) sendPunchToAllRemotes(hostinfo *HostInfo) {
|
|
||||||
hostinfo.remotes.ForEach(p.hm.GetPreferredRanges(), func(addr netip.AddrPort, preferred bool) {
|
|
||||||
p.metricPunchyTx.Inc(1)
|
|
||||||
p.punchConn.WriteTo([]byte{1}, addr)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
// Start wires the runtime dependencies and spawns the scheduler worker.
|
|
||||||
func (p *Punchy) Start(ctx context.Context, ifce EncWriter, hm *HostMap, lh lighthouseChecker) {
|
|
||||||
p.ctx = ctx
|
|
||||||
p.ifce = ifce
|
|
||||||
p.hm = hm
|
|
||||||
p.lh = lh
|
|
||||||
|
|
||||||
nb := make([]byte, 12, 12)
|
|
||||||
out := make([]byte, mtu)
|
|
||||||
empty := []byte{0}
|
|
||||||
|
|
||||||
go p.sched.Run(ctx, func(job holepunchJob) {
|
|
||||||
switch {
|
|
||||||
case job.target.IsValid():
|
|
||||||
if p.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
p.l.Debug("Punching", "target", job.target, "vpnAddr", job.vpnAddr)
|
|
||||||
}
|
|
||||||
p.metricHolepunchTx.Inc(1)
|
|
||||||
p.punchConn.WriteTo(empty, job.target)
|
|
||||||
case job.vpnAddr.IsValid():
|
|
||||||
// A nebula test packet to the host trying to contact us.
|
|
||||||
// In the case of a double nat or other difficult scenario, this may help establish a tunnel.
|
|
||||||
if p.l.Enabled(context.Background(), slog.LevelDebug) {
|
|
||||||
p.l.Debug("Sending a nebula test packet", "vpnAddr", job.vpnAddr)
|
|
||||||
}
|
|
||||||
p.ifce.SendMessageToVpnAddr(header.Test, header.TestRequest, job.vpnAddr, []byte(""), nb, out)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
|
|||||||
+41
-40
@@ -17,42 +17,42 @@ func TestNewPunchyFromConfig(t *testing.T) {
|
|||||||
c := config.NewC(l)
|
c := config.NewC(l)
|
||||||
|
|
||||||
// Test defaults
|
// Test defaults
|
||||||
p := NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p := NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.False(t, p.punch.Load())
|
assert.False(t, p.GetPunch())
|
||||||
assert.False(t, p.respond.Load())
|
assert.False(t, p.GetRespond())
|
||||||
assert.Equal(t, time.Second, time.Duration(p.delay.Load()))
|
assert.Equal(t, time.Second, p.GetDelay())
|
||||||
assert.Equal(t, 5*time.Second, time.Duration(p.respondDelay.Load()))
|
assert.Equal(t, 5*time.Second, p.GetRespondDelay())
|
||||||
|
|
||||||
// punchy deprecation
|
// punchy deprecation
|
||||||
c.Settings["punchy"] = true
|
c.Settings["punchy"] = true
|
||||||
p = NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p = NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.True(t, p.punch.Load())
|
assert.True(t, p.GetPunch())
|
||||||
|
|
||||||
// punchy.punch
|
// punchy.punch
|
||||||
c.Settings["punchy"] = map[string]any{"punch": true}
|
c.Settings["punchy"] = map[string]any{"punch": true}
|
||||||
p = NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p = NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.True(t, p.punch.Load())
|
assert.True(t, p.GetPunch())
|
||||||
|
|
||||||
// punch_back deprecation
|
// punch_back deprecation
|
||||||
c.Settings["punch_back"] = true
|
c.Settings["punch_back"] = true
|
||||||
p = NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p = NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.True(t, p.respond.Load())
|
assert.True(t, p.GetRespond())
|
||||||
|
|
||||||
// punchy.respond
|
// punchy.respond
|
||||||
c.Settings["punchy"] = map[string]any{"respond": true}
|
c.Settings["punchy"] = map[string]any{"respond": true}
|
||||||
c.Settings["punch_back"] = false
|
c.Settings["punch_back"] = false
|
||||||
p = NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p = NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.True(t, p.respond.Load())
|
assert.True(t, p.GetRespond())
|
||||||
|
|
||||||
// punchy.delay
|
// punchy.delay
|
||||||
c.Settings["punchy"] = map[string]any{"delay": "1m"}
|
c.Settings["punchy"] = map[string]any{"delay": "1m"}
|
||||||
p = NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p = NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.Equal(t, time.Minute, time.Duration(p.delay.Load()))
|
assert.Equal(t, time.Minute, p.GetDelay())
|
||||||
|
|
||||||
// punchy.respond_delay
|
// punchy.respond_delay
|
||||||
c.Settings["punchy"] = map[string]any{"respond_delay": "1m"}
|
c.Settings["punchy"] = map[string]any{"respond_delay": "1m"}
|
||||||
p = NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p = NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.Equal(t, time.Minute, time.Duration(p.respondDelay.Load()))
|
assert.Equal(t, time.Minute, p.GetRespondDelay())
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestPunchy_reload(t *testing.T) {
|
func TestPunchy_reload(t *testing.T) {
|
||||||
@@ -61,34 +61,35 @@ func TestPunchy_reload(t *testing.T) {
|
|||||||
delay, _ := time.ParseDuration("1m")
|
delay, _ := time.ParseDuration("1m")
|
||||||
require.NoError(t, c.LoadString(`
|
require.NoError(t, c.LoadString(`
|
||||||
punchy:
|
punchy:
|
||||||
punch: false
|
|
||||||
delay: 1m
|
delay: 1m
|
||||||
respond: false
|
respond: false
|
||||||
`))
|
`))
|
||||||
p := NewPunchyFromConfig(test.NewLogger(), c, nil)
|
p := NewPunchyFromConfig(test.NewLogger(), c)
|
||||||
assert.False(t, p.punch.Load())
|
assert.Equal(t, delay, p.GetDelay())
|
||||||
assert.Equal(t, delay, time.Duration(p.delay.Load()))
|
assert.False(t, p.GetRespond())
|
||||||
assert.False(t, p.respond.Load())
|
|
||||||
|
|
||||||
newDelay, _ := time.ParseDuration("10m")
|
newDelay, _ := time.ParseDuration("10m")
|
||||||
require.NoError(t, c.ReloadConfigString(`
|
require.NoError(t, c.ReloadConfigString(`
|
||||||
punchy:
|
punchy:
|
||||||
punch: true
|
|
||||||
delay: 10m
|
delay: 10m
|
||||||
respond: true
|
respond: true
|
||||||
`))
|
`))
|
||||||
p.reload(c, false)
|
p.reload(c, false)
|
||||||
assert.True(t, p.punch.Load())
|
assert.Equal(t, newDelay, p.GetDelay())
|
||||||
assert.Equal(t, newDelay, time.Duration(p.delay.Load()))
|
assert.True(t, p.GetRespond())
|
||||||
assert.True(t, p.respond.Load())
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// The tests below pin the shape of each log line Punchy produces so changes
|
// The tests below pin the shape of each log line Punchy produces so changes
|
||||||
// cannot silently break whatever operators are grepping for. The assertions
|
// cannot silently break whatever operators are grepping for. The assertions
|
||||||
// are on the structured message + attrs (e.g. "punchy.respond changed" with
|
// are on the structured message + attrs (e.g. "punchy.respond changed" with
|
||||||
// a respond=true field) rather than a formatted string. Tests filter by
|
// a respond=true field) rather than a formatted string.
|
||||||
// message rather than asserting total entry counts so unrelated info lines
|
//
|
||||||
// are tolerated without being locked into the format.
|
// Punchy.reload also emits a spurious "Changing punchy.punch with reload is
|
||||||
|
// not supported" warning whenever any key under punchy changes, because of
|
||||||
|
// the c.HasChanged("punchy") fallback kept for the deprecated top-level
|
||||||
|
// punchy form. The tests filter by message rather than asserting total
|
||||||
|
// entry counts so that warning is tolerated without being locked into
|
||||||
|
// the format.
|
||||||
|
|
||||||
type capturedEntry struct {
|
type capturedEntry struct {
|
||||||
Level slog.Level
|
Level slog.Level
|
||||||
@@ -144,7 +145,7 @@ func TestPunchy_LogFormat_InitialEnabled(t *testing.T) {
|
|||||||
c := config.NewC(test.NewLogger())
|
c := config.NewC(test.NewLogger())
|
||||||
require.NoError(t, c.LoadString(`punchy: {punch: true}`))
|
require.NoError(t, c.LoadString(`punchy: {punch: true}`))
|
||||||
|
|
||||||
NewPunchyFromConfig(l, c, nil)
|
NewPunchyFromConfig(l, c)
|
||||||
|
|
||||||
entry := findEntry(t, hook.entries, "punchy enabled")
|
entry := findEntry(t, hook.entries, "punchy enabled")
|
||||||
assert.Equal(t, slog.LevelInfo, entry.Level)
|
assert.Equal(t, slog.LevelInfo, entry.Level)
|
||||||
@@ -156,32 +157,32 @@ func TestPunchy_LogFormat_InitialDisabled(t *testing.T) {
|
|||||||
c := config.NewC(test.NewLogger())
|
c := config.NewC(test.NewLogger())
|
||||||
require.NoError(t, c.LoadString(`punchy: {punch: false}`))
|
require.NoError(t, c.LoadString(`punchy: {punch: false}`))
|
||||||
|
|
||||||
NewPunchyFromConfig(l, c, nil)
|
NewPunchyFromConfig(l, c)
|
||||||
|
|
||||||
entry := findEntry(t, hook.entries, "punchy disabled")
|
entry := findEntry(t, hook.entries, "punchy disabled")
|
||||||
assert.Equal(t, slog.LevelInfo, entry.Level)
|
assert.Equal(t, slog.LevelInfo, entry.Level)
|
||||||
assert.Empty(t, entry.Attrs)
|
assert.Empty(t, entry.Attrs)
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestPunchy_LogFormat_ReloadPunch(t *testing.T) {
|
func TestPunchy_LogFormat_ReloadPunchUnsupported(t *testing.T) {
|
||||||
l, hook := newCapturingPunchyLogger(t)
|
l, hook := newCapturingPunchyLogger(t)
|
||||||
c := config.NewC(test.NewLogger())
|
c := config.NewC(test.NewLogger())
|
||||||
require.NoError(t, c.LoadString(`punchy: {punch: false}`))
|
require.NoError(t, c.LoadString(`punchy: {punch: false}`))
|
||||||
NewPunchyFromConfig(l, c, nil)
|
NewPunchyFromConfig(l, c)
|
||||||
hook.entries = nil
|
hook.entries = nil
|
||||||
|
|
||||||
require.NoError(t, c.ReloadConfigString(`punchy: {punch: true}`))
|
require.NoError(t, c.ReloadConfigString(`punchy: {punch: true}`))
|
||||||
|
|
||||||
entry := findEntry(t, hook.entries, "punchy.punch changed")
|
entry := findEntry(t, hook.entries, "Changing punchy.punch with reload is not supported, ignoring.")
|
||||||
assert.Equal(t, slog.LevelInfo, entry.Level)
|
assert.Equal(t, slog.LevelWarn, entry.Level)
|
||||||
assert.Equal(t, map[string]any{"punch": true}, entry.Attrs)
|
assert.Empty(t, entry.Attrs)
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestPunchy_LogFormat_ReloadRespond(t *testing.T) {
|
func TestPunchy_LogFormat_ReloadRespond(t *testing.T) {
|
||||||
l, hook := newCapturingPunchyLogger(t)
|
l, hook := newCapturingPunchyLogger(t)
|
||||||
c := config.NewC(test.NewLogger())
|
c := config.NewC(test.NewLogger())
|
||||||
require.NoError(t, c.LoadString(`punchy: {respond: false}`))
|
require.NoError(t, c.LoadString(`punchy: {respond: false}`))
|
||||||
NewPunchyFromConfig(l, c, nil)
|
NewPunchyFromConfig(l, c)
|
||||||
hook.entries = nil
|
hook.entries = nil
|
||||||
|
|
||||||
require.NoError(t, c.ReloadConfigString(`punchy: {respond: true}`))
|
require.NoError(t, c.ReloadConfigString(`punchy: {respond: true}`))
|
||||||
@@ -195,7 +196,7 @@ func TestPunchy_LogFormat_ReloadDelay(t *testing.T) {
|
|||||||
l, hook := newCapturingPunchyLogger(t)
|
l, hook := newCapturingPunchyLogger(t)
|
||||||
c := config.NewC(test.NewLogger())
|
c := config.NewC(test.NewLogger())
|
||||||
require.NoError(t, c.LoadString(`punchy: {delay: 1s}`))
|
require.NoError(t, c.LoadString(`punchy: {delay: 1s}`))
|
||||||
NewPunchyFromConfig(l, c, nil)
|
NewPunchyFromConfig(l, c)
|
||||||
hook.entries = nil
|
hook.entries = nil
|
||||||
|
|
||||||
require.NoError(t, c.ReloadConfigString(`punchy: {delay: 10s}`))
|
require.NoError(t, c.ReloadConfigString(`punchy: {delay: 10s}`))
|
||||||
@@ -209,7 +210,7 @@ func TestPunchy_LogFormat_ReloadTargetAllRemotes(t *testing.T) {
|
|||||||
l, hook := newCapturingPunchyLogger(t)
|
l, hook := newCapturingPunchyLogger(t)
|
||||||
c := config.NewC(test.NewLogger())
|
c := config.NewC(test.NewLogger())
|
||||||
require.NoError(t, c.LoadString(`punchy: {target_all_remotes: false}`))
|
require.NoError(t, c.LoadString(`punchy: {target_all_remotes: false}`))
|
||||||
NewPunchyFromConfig(l, c, nil)
|
NewPunchyFromConfig(l, c)
|
||||||
hook.entries = nil
|
hook.entries = nil
|
||||||
|
|
||||||
require.NoError(t, c.ReloadConfigString(`punchy: {target_all_remotes: true}`))
|
require.NoError(t, c.ReloadConfigString(`punchy: {target_all_remotes: true}`))
|
||||||
@@ -223,7 +224,7 @@ func TestPunchy_LogFormat_ReloadRespondDelay(t *testing.T) {
|
|||||||
l, hook := newCapturingPunchyLogger(t)
|
l, hook := newCapturingPunchyLogger(t)
|
||||||
c := config.NewC(test.NewLogger())
|
c := config.NewC(test.NewLogger())
|
||||||
require.NoError(t, c.LoadString(`punchy: {respond_delay: 5s}`))
|
require.NoError(t, c.LoadString(`punchy: {respond_delay: 5s}`))
|
||||||
NewPunchyFromConfig(l, c, nil)
|
NewPunchyFromConfig(l, c)
|
||||||
hook.entries = nil
|
hook.entries = nil
|
||||||
|
|
||||||
require.NoError(t, c.ReloadConfigString(`punchy: {respond_delay: 15s}`))
|
require.NoError(t, c.ReloadConfigString(`punchy: {respond_delay: 15s}`))
|
||||||
|
|||||||
@@ -1,84 +0,0 @@
|
|||||||
package nebula
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"sync"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Scheduler is an allocation-conscious dispatch primitive for delayed work.
|
|
||||||
// Pending items are handed to time.AfterFunc, and ready items land on a worker
|
|
||||||
// channel for centralized dispatch in fire-time order.
|
|
||||||
//
|
|
||||||
// Pick a Scheduler when fire timing matters (exact deadlines, no bucketing) or when the scheduling
|
|
||||||
// rate is uneven enough that idle CPU matters. Each fire is a runtime-spawned goroutine running the callback before
|
|
||||||
// delivering to the worker, which is fine at sparse rates but adds up at line rate.
|
|
||||||
//
|
|
||||||
// Pick a TimerWheel when scheduling is high-rate and uniform: its O(1) insert, internal item cache,
|
|
||||||
// and bucket-batched dispatch are cheaper at scale.
|
|
||||||
// The caller drives the tick loop (Advance/Purge) and pays for fires at bucket boundaries rather than exact deadlines.
|
|
||||||
type Scheduler[T any] struct {
|
|
||||||
queue chan T
|
|
||||||
pool sync.Pool
|
|
||||||
}
|
|
||||||
|
|
||||||
type schedItem[T any] struct {
|
|
||||||
val T
|
|
||||||
ctx context.Context
|
|
||||||
s *Scheduler[T]
|
|
||||||
timer *time.Timer
|
|
||||||
fire func()
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewScheduler builds a Scheduler whose worker channel is sized to queueSize.
|
|
||||||
// The buffer absorbs bursts of timers firing close together without
|
|
||||||
// blocking the runtime's callback goroutines on the worker.
|
|
||||||
func NewScheduler[T any](queueSize int) *Scheduler[T] {
|
|
||||||
s := &Scheduler[T]{
|
|
||||||
queue: make(chan T, queueSize),
|
|
||||||
}
|
|
||||||
s.pool.New = func() any {
|
|
||||||
si := &schedItem[T]{s: s}
|
|
||||||
// fire is allocated exactly once per pool-resident item.
|
|
||||||
// The closure captures only `si`, which stays stable for the item's lifetime.
|
|
||||||
si.fire = func() {
|
|
||||||
select {
|
|
||||||
case si.s.queue <- si.val:
|
|
||||||
case <-si.ctx.Done():
|
|
||||||
}
|
|
||||||
var zero T
|
|
||||||
si.val = zero
|
|
||||||
si.ctx = nil
|
|
||||||
si.s.pool.Put(si)
|
|
||||||
}
|
|
||||||
return si
|
|
||||||
}
|
|
||||||
return s
|
|
||||||
}
|
|
||||||
|
|
||||||
// Schedule arranges item to be delivered to the worker after delay.
|
|
||||||
// The runtime's timer heap handles the wait, so the scheduler itself burns no CPU while idle.
|
|
||||||
// The callback observes ctx: if ctx is cancelled before the timer fires, the item is dropped instead of queued.
|
|
||||||
func (s *Scheduler[T]) Schedule(ctx context.Context, item T, delay time.Duration) {
|
|
||||||
si := s.pool.Get().(*schedItem[T])
|
|
||||||
si.val = item
|
|
||||||
si.ctx = ctx
|
|
||||||
if si.timer == nil {
|
|
||||||
si.timer = time.AfterFunc(delay, si.fire)
|
|
||||||
} else {
|
|
||||||
si.timer.Reset(delay)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Run drains the worker queue, calling fn for each item. Returns when ctx is cancelled.
|
|
||||||
// Tests that want deterministic timing should drive the queue directly rather than going through Schedule + Run.
|
|
||||||
func (s *Scheduler[T]) Run(ctx context.Context, fn func(T)) {
|
|
||||||
for {
|
|
||||||
select {
|
|
||||||
case <-ctx.Done():
|
|
||||||
return
|
|
||||||
case item := <-s.queue:
|
|
||||||
fn(item)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,79 +0,0 @@
|
|||||||
package nebula
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestScheduler_PooledReuse(t *testing.T) {
|
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
|
||||||
defer cancel()
|
|
||||||
|
|
||||||
s := NewScheduler[int](16)
|
|
||||||
delivered := make(chan int, 256)
|
|
||||||
go s.Run(ctx, func(item int) { delivered <- item })
|
|
||||||
|
|
||||||
const N = 100
|
|
||||||
for i := 0; i < N; i++ {
|
|
||||||
s.Schedule(ctx, i, time.Millisecond)
|
|
||||||
}
|
|
||||||
|
|
||||||
deadline := time.After(2 * time.Second)
|
|
||||||
got := 0
|
|
||||||
for got < N {
|
|
||||||
select {
|
|
||||||
case <-delivered:
|
|
||||||
got++
|
|
||||||
case <-deadline:
|
|
||||||
t.Fatalf("only %d/%d items delivered", got, N)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkScheduler_Schedule reports allocations per Schedule call.
|
|
||||||
// In steady state the Scheduler's sync.Pool means we should see zero allocs per op once the pool warms up.
|
|
||||||
func BenchmarkScheduler_Schedule(b *testing.B) {
|
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
|
||||||
defer cancel()
|
|
||||||
|
|
||||||
s := NewScheduler[int](b.N)
|
|
||||||
go s.Run(ctx, func(int) {})
|
|
||||||
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
s.Schedule(ctx, i, time.Microsecond)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BenchmarkBareAfterFunc is the comparison baseline.
|
|
||||||
// What we'd pay per Schedule if Punchy called time.AfterFunc directly without the pooled Scheduler.
|
|
||||||
// Allocates a *time.Timer plus a closure each call.
|
|
||||||
func BenchmarkBareAfterFunc(b *testing.B) {
|
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
|
||||||
defer cancel()
|
|
||||||
|
|
||||||
queue := make(chan int, b.N)
|
|
||||||
go func() {
|
|
||||||
for {
|
|
||||||
select {
|
|
||||||
case <-ctx.Done():
|
|
||||||
return
|
|
||||||
case <-queue:
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
|
|
||||||
b.ReportAllocs()
|
|
||||||
b.ResetTimer()
|
|
||||||
for i := 0; i < b.N; i++ {
|
|
||||||
i := i
|
|
||||||
time.AfterFunc(time.Microsecond, func() {
|
|
||||||
select {
|
|
||||||
case queue <- i:
|
|
||||||
case <-ctx.Done():
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+21
-38
@@ -27,20 +27,21 @@ type SSHServer struct {
|
|||||||
commands *radix.Tree
|
commands *radix.Tree
|
||||||
listener net.Listener
|
listener net.Listener
|
||||||
|
|
||||||
// ctx parents per-Run contexts. Cancelling it (e.g. via Control.Stop) tears the server down even
|
// Call the cancel() function to stop all active sessions
|
||||||
// across reloads, since each Run derives a fresh child rather than reusing this one directly.
|
ctx context.Context
|
||||||
ctx context.Context
|
cancel func()
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewSSHServer creates a new ssh server rigged with default commands and prepares to listen.
|
// NewSSHServer creates a new ssh server rigged with default commands and prepares to listen
|
||||||
// The ssh server's context is parented off the supplied ctx so cancelling it
|
func NewSSHServer(l *slog.Logger) (*SSHServer, error) {
|
||||||
// (e.g. on Control.Stop) tears down active sessions and closes the listener.
|
|
||||||
func NewSSHServer(ctx context.Context, l *slog.Logger) (*SSHServer, error) {
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
s := &SSHServer{
|
s := &SSHServer{
|
||||||
trustedKeys: make(map[string]map[string]bool),
|
trustedKeys: make(map[string]map[string]bool),
|
||||||
l: l,
|
l: l,
|
||||||
commands: radix.New(),
|
commands: radix.New(),
|
||||||
ctx: ctx,
|
ctx: ctx,
|
||||||
|
cancel: cancel,
|
||||||
}
|
}
|
||||||
|
|
||||||
cc := ssh.CertChecker{
|
cc := ssh.CertChecker{
|
||||||
@@ -150,51 +151,28 @@ func (s *SSHServer) RegisterCommand(c *Command) {
|
|||||||
s.commands.Insert(c.Name, c)
|
s.commands.Insert(c.Name, c)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Run begins listening and accepting connections. Each invocation derives a fresh per-Run context
|
// Run begins listening and accepting connections
|
||||||
// from the constructor-supplied ctx so a Stop+Run sequence (used by config reload) starts clean
|
|
||||||
// rather than carrying a permanently-cancelled context across runs.
|
|
||||||
func (s *SSHServer) Run(addr string) error {
|
func (s *SSHServer) Run(addr string) error {
|
||||||
if s.ctx.Err() != nil {
|
var err error
|
||||||
return s.ctx.Err()
|
s.listener, err = net.Listen("tcp", addr)
|
||||||
}
|
|
||||||
|
|
||||||
listener, err := net.Listen("tcp", addr)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
// s.listener is the public handle Stop uses to interrupt the active run; listener (the local) is what
|
|
||||||
// this run owns. They start equal but a fast reload may overwrite s.listener with the next run's
|
|
||||||
// listener before this run's watcher fires, so each run must close its own listener via the local
|
|
||||||
// reference.
|
|
||||||
s.listener = listener
|
|
||||||
|
|
||||||
runCtx, cancel := context.WithCancel(s.ctx)
|
|
||||||
defer cancel()
|
|
||||||
|
|
||||||
// Close the listener when this run's context is cancelled. That can come from the parent
|
|
||||||
// (Control.Stop), from Run returning normally (defer cancel above), or transitively when a sibling
|
|
||||||
// run cancels through Stop closing the listener. net.Listener.Close is idempotent so a duplicate
|
|
||||||
// close from Stop is benign.
|
|
||||||
go func() {
|
|
||||||
<-runCtx.Done()
|
|
||||||
if err := listener.Close(); err != nil && !errors.Is(err, net.ErrClosed) {
|
|
||||||
s.l.Warn("Failed to close the sshd listener", "error", err)
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
|
|
||||||
s.l.Info("SSH server is listening", "sshListener", addr)
|
s.l.Info("SSH server is listening", "sshListener", addr)
|
||||||
|
|
||||||
// Run loops until there is an error
|
// Run loops until there is an error
|
||||||
s.run(runCtx, listener)
|
s.run()
|
||||||
|
s.closeSessions()
|
||||||
|
|
||||||
s.l.Info("SSH server stopped listening")
|
s.l.Info("SSH server stopped listening")
|
||||||
// We don't return an error because run logs for us
|
// We don't return an error because run logs for us
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *SSHServer) run(ctx context.Context, listener net.Listener) {
|
func (s *SSHServer) run() {
|
||||||
for {
|
for {
|
||||||
c, err := listener.Accept()
|
c, err := s.listener.Accept()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if !errors.Is(err, net.ErrClosed) {
|
if !errors.Is(err, net.ErrClosed) {
|
||||||
s.l.Warn("Error in listener, shutting down", "error", err)
|
s.l.Warn("Error in listener, shutting down", "error", err)
|
||||||
@@ -206,7 +184,7 @@ func (s *SSHServer) run(ctx context.Context, listener net.Listener) {
|
|||||||
// Ensure that a bad client doesn't hurt us by checking for the parent context
|
// Ensure that a bad client doesn't hurt us by checking for the parent context
|
||||||
// cancellation before calling NewServerConn, and forcing the socket to close when
|
// cancellation before calling NewServerConn, and forcing the socket to close when
|
||||||
// the context is cancelled.
|
// the context is cancelled.
|
||||||
sessionContext, sessionCancel := context.WithCancel(ctx)
|
sessionContext, sessionCancel := context.WithCancel(s.ctx)
|
||||||
go func() {
|
go func() {
|
||||||
<-sessionContext.Done()
|
<-sessionContext.Done()
|
||||||
c.Close()
|
c.Close()
|
||||||
@@ -249,9 +227,14 @@ func (s *SSHServer) run(ctx context.Context, listener net.Listener) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (s *SSHServer) Stop() {
|
func (s *SSHServer) Stop() {
|
||||||
|
// Close the listener, this will cause all session to terminate as well, see SSHServer.Run
|
||||||
if s.listener != nil {
|
if s.listener != nil {
|
||||||
if err := s.listener.Close(); err != nil {
|
if err := s.listener.Close(); err != nil {
|
||||||
s.l.Warn("Failed to close the sshd listener", "error", err)
|
s.l.Warn("Failed to close the sshd listener", "error", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (s *SSHServer) closeSessions() {
|
||||||
|
s.cancel()
|
||||||
|
}
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user