2019-03-29 14:23:19 +00:00
|
|
|
#include <utp/session.hpp>
|
2019-01-10 19:41:51 +00:00
|
|
|
|
2019-03-29 14:23:19 +00:00
|
|
|
#include <utp/linklayer.hpp>
|
2018-12-12 02:52:51 +00:00
|
|
|
#include <messages/discard.hpp>
|
|
|
|
#include <messages/link_intro.hpp>
|
2019-03-26 19:30:10 +00:00
|
|
|
#include <util/metrics.hpp>
|
|
|
|
|
2018-09-04 12:41:25 +00:00
|
|
|
namespace llarp
|
|
|
|
{
|
|
|
|
namespace utp
|
|
|
|
{
|
2019-01-26 15:40:58 +00:00
|
|
|
using namespace std::placeholders;
|
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
void
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::OnLinkEstablished(ILinkLayer* p)
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
|
|
|
parent = p;
|
|
|
|
EnterState(eLinkEstablished);
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("link established with ", remoteAddr);
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2019-02-11 19:45:42 +00:00
|
|
|
Crypto*
|
|
|
|
Session::OurCrypto()
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
return parent->OurCrypto();
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-06 11:46:19 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
/// pump tx queue
|
|
|
|
void
|
|
|
|
Session::PumpWrite()
|
|
|
|
{
|
|
|
|
if(!sock)
|
|
|
|
return;
|
|
|
|
ssize_t expect = 0;
|
2019-05-08 15:42:38 +00:00
|
|
|
std::vector< utp_iovec > send;
|
2018-12-17 20:46:08 +00:00
|
|
|
for(const auto& vec : vecq)
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
expect += vec.iov_len;
|
2019-05-08 15:42:38 +00:00
|
|
|
send.emplace_back(vec);
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
if(expect)
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2019-05-08 15:42:38 +00:00
|
|
|
ssize_t s = utp_writev(sock, send.data(), send.size());
|
2019-02-25 12:46:29 +00:00
|
|
|
if(s < 0)
|
|
|
|
return;
|
2019-03-29 15:26:44 +00:00
|
|
|
if(s > 0)
|
|
|
|
lastSend = parent->Now();
|
|
|
|
|
2019-03-26 19:30:10 +00:00
|
|
|
METRICS_DYNAMIC_INT_UPDATE(
|
|
|
|
"utp.session.tx", RouterID(remoteRC.pubkey).ToString().c_str(), s);
|
2019-02-15 22:19:19 +00:00
|
|
|
m_TXRate += s;
|
2019-02-25 12:46:29 +00:00
|
|
|
size_t sz = s;
|
2019-02-25 12:51:01 +00:00
|
|
|
while(vecq.size() && sz >= vecq.front().iov_len)
|
2018-09-12 13:29:42 +00:00
|
|
|
{
|
2019-02-25 12:46:29 +00:00
|
|
|
sz -= vecq.front().iov_len;
|
2018-12-17 20:46:08 +00:00
|
|
|
vecq.pop_front();
|
|
|
|
sendq.pop_front();
|
2018-09-12 13:29:42 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
if(vecq.size())
|
2018-09-12 13:29:42 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
auto& front = vecq.front();
|
2019-02-25 12:46:29 +00:00
|
|
|
front.iov_len -= sz;
|
|
|
|
front.iov_base = ((byte_t*)front.iov_base) + sz;
|
2018-09-12 13:29:42 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
/// prune expired inbound messages
|
|
|
|
void
|
|
|
|
Session::PruneInboundMessages(llarp_time_t now)
|
|
|
|
{
|
|
|
|
auto itr = m_RecvMsgs.begin();
|
|
|
|
while(itr != m_RecvMsgs.end())
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
if(itr->second.IsExpired(now))
|
|
|
|
itr = m_RecvMsgs.erase(itr);
|
|
|
|
else
|
|
|
|
++itr;
|
2018-09-06 11:46:19 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-06 11:46:19 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
void
|
|
|
|
Session::OutboundLinkEstablished(LinkLayer* p)
|
|
|
|
{
|
|
|
|
OnLinkEstablished(p);
|
2018-09-09 11:23:21 +00:00
|
|
|
OutboundHandshake();
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-06 11:46:19 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
bool
|
|
|
|
Session::DoKeyExchange(transport_dh_func dh, SharedSecret& K,
|
|
|
|
const KeyExchangeNonce& n, const PubKey& other,
|
2019-01-02 01:04:04 +00:00
|
|
|
const SecretKey& secret)
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
|
|
|
ShortHash t_h;
|
2019-01-02 01:04:04 +00:00
|
|
|
static constexpr size_t TMP_SIZE = 64;
|
|
|
|
static_assert(SharedSecret::SIZE + KeyExchangeNonce::SIZE == TMP_SIZE,
|
|
|
|
"Invalid sizes");
|
|
|
|
|
|
|
|
AlignedBuffer< TMP_SIZE > tmp;
|
2019-01-02 01:03:53 +00:00
|
|
|
std::copy(K.begin(), K.end(), tmp.begin());
|
|
|
|
std::copy(n.begin(), n.end(), tmp.begin() + K.size());
|
2018-12-17 20:46:08 +00:00
|
|
|
// t_h = HS(K + L.n)
|
2019-02-11 19:45:42 +00:00
|
|
|
if(!OurCrypto()->shorthash(t_h, llarp_buffer_t(tmp)))
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to mix key to ", remoteAddr);
|
2018-12-17 20:46:08 +00:00
|
|
|
return false;
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
// K = TKE(a.p, B_a.e, sk, t_h)
|
2019-01-02 01:04:04 +00:00
|
|
|
if(!dh(K, other, secret, t_h))
|
2018-12-16 20:34:04 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("key exchange with ", other, " failed");
|
2018-12-17 20:46:08 +00:00
|
|
|
return false;
|
2018-12-16 20:34:04 +00:00
|
|
|
}
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("keys mixed with session to ", remoteAddr);
|
2018-12-17 20:46:08 +00:00
|
|
|
return true;
|
|
|
|
}
|
2018-12-16 20:34:04 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
bool
|
|
|
|
Session::MutateKey(SharedSecret& K, const AlignedBuffer< 24 >& A)
|
|
|
|
{
|
|
|
|
AlignedBuffer< 56 > tmp;
|
2019-02-02 23:12:42 +00:00
|
|
|
llarp_buffer_t buf{tmp};
|
2019-01-02 01:03:53 +00:00
|
|
|
std::copy(K.begin(), K.end(), buf.cur);
|
2018-12-17 20:46:08 +00:00
|
|
|
buf.cur += K.size();
|
2019-01-02 01:04:04 +00:00
|
|
|
std::copy(A.begin(), A.end(), buf.cur);
|
2018-12-17 20:46:08 +00:00
|
|
|
buf.cur = buf.base;
|
2019-02-11 19:45:42 +00:00
|
|
|
return OurCrypto()->shorthash(K, buf);
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
void
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::Tick(llarp_time_t now)
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
|
|
|
PruneInboundMessages(now);
|
2019-02-15 22:19:19 +00:00
|
|
|
m_TXRate = 0;
|
|
|
|
m_RXRate = 0;
|
2019-03-26 20:04:41 +00:00
|
|
|
METRICS_DYNAMIC_UPDATE("utp.session.sendq",
|
|
|
|
RouterID(remoteRC.pubkey).ToString().c_str(),
|
|
|
|
sendq.size());
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
/// low level read
|
|
|
|
bool
|
|
|
|
Session::Recv(const byte_t* buf, size_t sz)
|
|
|
|
{
|
|
|
|
// mark we are alive
|
|
|
|
Alive();
|
2019-02-15 22:19:19 +00:00
|
|
|
m_RXRate += sz;
|
2018-12-17 20:46:08 +00:00
|
|
|
size_t s = sz;
|
2019-03-26 19:30:10 +00:00
|
|
|
METRICS_DYNAMIC_INT_UPDATE(
|
|
|
|
"utp.session.rx", RouterID(remoteRC.pubkey).ToString().c_str(), s);
|
2018-12-17 20:46:08 +00:00
|
|
|
// process leftovers
|
|
|
|
if(recvBufOffset)
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
auto left = FragmentBufferSize - recvBufOffset;
|
|
|
|
if(s >= left)
|
2018-09-07 17:41:49 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
// yes it fills it
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("process leftovers, offset=", recvBufOffset, " sz=", s,
|
|
|
|
" left=", left);
|
2019-01-02 01:03:53 +00:00
|
|
|
std::copy(buf, buf + left, recvBuf.begin() + recvBufOffset);
|
2018-12-17 20:46:08 +00:00
|
|
|
s -= left;
|
2018-09-07 20:36:06 +00:00
|
|
|
recvBufOffset = 0;
|
2018-12-17 20:46:08 +00:00
|
|
|
buf += left;
|
2019-01-02 01:04:04 +00:00
|
|
|
if(!VerifyThenDecrypt(recvBuf.data()))
|
2018-09-07 17:41:49 +00:00
|
|
|
return false;
|
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
// process full fragments
|
|
|
|
while(s >= FragmentBufferSize)
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
recvBufOffset = 0;
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("process full sz=", s);
|
2018-12-17 20:46:08 +00:00
|
|
|
if(!VerifyThenDecrypt(buf))
|
2018-09-04 12:41:25 +00:00
|
|
|
return false;
|
2018-12-17 20:46:08 +00:00
|
|
|
buf += FragmentBufferSize;
|
|
|
|
s -= FragmentBufferSize;
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
if(s)
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
// hold onto leftovers
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("leftovers sz=", s);
|
2019-01-02 01:03:53 +00:00
|
|
|
std::copy(buf, buf + s, recvBuf.begin() + recvBufOffset);
|
2018-12-17 20:46:08 +00:00
|
|
|
recvBufOffset += s;
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
return true;
|
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
bool
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::TimedOut(llarp_time_t now) const
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
2019-05-08 12:17:48 +00:00
|
|
|
if(state == eInitial || state == eLinkEstablished)
|
2019-03-26 13:51:57 +00:00
|
|
|
return false;
|
2019-03-22 18:23:33 +00:00
|
|
|
if(sendq.size() >= MaxSendQueueSize)
|
|
|
|
{
|
2019-03-29 15:26:44 +00:00
|
|
|
return now - lastSend > 5000;
|
2019-03-22 18:23:33 +00:00
|
|
|
}
|
2019-03-22 11:44:28 +00:00
|
|
|
// let utp manage this
|
|
|
|
return state == eClose;
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2019-04-02 09:03:53 +00:00
|
|
|
PubKey
|
|
|
|
Session::GetPubKey() const
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
|
|
|
return remoteRC.pubkey;
|
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2018-12-19 16:17:41 +00:00
|
|
|
Addr
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::GetRemoteEndpoint() const
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
return remoteAddr;
|
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2018-12-16 20:34:04 +00:00
|
|
|
/// base constructor
|
2018-12-17 20:46:08 +00:00
|
|
|
Session::Session(LinkLayer* p)
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2019-03-26 13:51:57 +00:00
|
|
|
state = eInitial;
|
2018-12-17 20:46:08 +00:00
|
|
|
m_NextTXMsgID = 0;
|
|
|
|
m_NextRXMsgID = 0;
|
|
|
|
parent = p;
|
2018-09-07 17:41:49 +00:00
|
|
|
remoteTransportPubKey.Zero();
|
2018-09-08 15:53:20 +00:00
|
|
|
|
2018-12-03 18:28:16 +00:00
|
|
|
gotLIM = false;
|
2018-09-06 11:46:19 +00:00
|
|
|
recvBufOffset = 0;
|
2018-12-17 20:46:08 +00:00
|
|
|
|
|
|
|
lastActive = parent->Now();
|
2018-09-06 11:46:19 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
|
2019-04-02 09:03:53 +00:00
|
|
|
bool
|
|
|
|
Session::ShouldPing() const
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2019-04-17 14:46:00 +00:00
|
|
|
if(state != eSessionReady)
|
|
|
|
return false;
|
|
|
|
const auto dlt = parent->Now() - lastActive;
|
2019-04-02 09:03:53 +00:00
|
|
|
return dlt >= 10000;
|
2019-04-25 23:21:19 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
|
|
|
|
ILinkLayer*
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::GetLinkLayer() const
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
|
|
|
return parent;
|
2018-09-08 15:53:20 +00:00
|
|
|
}
|
|
|
|
|
2019-01-04 12:43:41 +00:00
|
|
|
void
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::Pump()
|
2019-01-04 12:43:41 +00:00
|
|
|
{
|
|
|
|
// pump write queue
|
|
|
|
PumpWrite();
|
|
|
|
// prune inbound messages
|
|
|
|
PruneInboundMessages(parent->Now());
|
|
|
|
}
|
|
|
|
|
2018-10-29 16:48:36 +00:00
|
|
|
bool
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::SendMessageBuffer(const llarp_buffer_t& buf)
|
2018-10-29 16:48:36 +00:00
|
|
|
{
|
|
|
|
if(sendq.size() >= MaxSendQueueSize)
|
2019-05-08 12:50:33 +00:00
|
|
|
{
|
|
|
|
// pump write queue if we seem to be full
|
|
|
|
PumpWrite();
|
|
|
|
}
|
|
|
|
if(sendq.size() >= MaxSendQueueSize)
|
|
|
|
{
|
|
|
|
// we didn't pump anything wtf
|
|
|
|
// this means we're stalled
|
2018-10-29 16:48:36 +00:00
|
|
|
return false;
|
2019-05-08 12:50:33 +00:00
|
|
|
}
|
2018-12-17 20:46:08 +00:00
|
|
|
size_t sz = buf.sz;
|
|
|
|
byte_t* ptr = buf.base;
|
|
|
|
uint32_t msgid = m_NextTXMsgID++;
|
2018-10-29 16:48:36 +00:00
|
|
|
while(sz)
|
|
|
|
{
|
|
|
|
uint32_t s = std::min(FragmentBodyPayloadSize, sz);
|
2018-12-17 20:46:08 +00:00
|
|
|
if(!EncryptThenHash(ptr, msgid, s, sz - s))
|
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("EncryptThenHash failed?!");
|
2018-12-17 20:46:08 +00:00
|
|
|
return false;
|
|
|
|
}
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("encrypted ", s, " bytes");
|
2018-10-29 16:48:36 +00:00
|
|
|
ptr += s;
|
|
|
|
sz -= s;
|
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2018-09-08 15:53:20 +00:00
|
|
|
bool
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::SendKeepAlive()
|
2018-09-08 15:53:20 +00:00
|
|
|
{
|
2019-04-17 14:46:00 +00:00
|
|
|
if(ShouldPing())
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
2019-04-02 09:03:53 +00:00
|
|
|
DiscardMessage msg;
|
|
|
|
std::array< byte_t, 128 > tmp;
|
|
|
|
llarp_buffer_t buf(tmp);
|
|
|
|
if(!msg.BEncode(&buf))
|
|
|
|
return false;
|
|
|
|
buf.sz = buf.cur - buf.base;
|
|
|
|
buf.cur = buf.base;
|
|
|
|
return this->SendMessageBuffer(buf);
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
|
|
|
return true;
|
2018-09-08 15:53:20 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
void
|
2018-12-17 20:46:08 +00:00
|
|
|
Session::OutboundHandshake()
|
2018-09-08 15:53:20 +00:00
|
|
|
{
|
2019-02-02 23:12:42 +00:00
|
|
|
std::array< byte_t, LinkIntroMessage::MaxSize > tmp;
|
|
|
|
llarp_buffer_t buf(tmp);
|
2018-09-09 11:23:21 +00:00
|
|
|
// build our RC
|
2018-09-08 15:53:20 +00:00
|
|
|
LinkIntroMessage msg;
|
2018-12-17 20:46:08 +00:00
|
|
|
msg.rc = parent->GetOurRC();
|
2019-02-11 19:45:42 +00:00
|
|
|
if(!msg.rc.Verify(OurCrypto(), parent->Now()))
|
2018-09-09 11:23:21 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("our RC is invalid? closing session to", remoteAddr);
|
2018-09-09 11:23:21 +00:00
|
|
|
Close();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
msg.N.Randomize();
|
|
|
|
msg.P = DefaultLinkSessionLifetime;
|
2018-12-17 20:46:08 +00:00
|
|
|
if(!msg.Sign(parent->Sign))
|
2018-09-08 15:53:20 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to sign LIM for outbound handshake to ", remoteAddr);
|
2018-09-08 15:53:20 +00:00
|
|
|
Close();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
// encode
|
|
|
|
if(!msg.BEncode(&buf))
|
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to encode LIM for handshake to ", remoteAddr);
|
2018-09-08 15:53:20 +00:00
|
|
|
Close();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
// rewind
|
2018-12-03 18:28:16 +00:00
|
|
|
buf.sz = buf.cur - buf.base;
|
2018-09-08 15:53:20 +00:00
|
|
|
buf.cur = buf.base;
|
|
|
|
// send
|
|
|
|
if(!SendMessageBuffer(buf))
|
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to send handshake to ", remoteAddr);
|
2018-09-08 15:53:20 +00:00
|
|
|
Close();
|
|
|
|
return;
|
|
|
|
}
|
2019-01-26 15:40:58 +00:00
|
|
|
|
2019-02-11 19:45:42 +00:00
|
|
|
if(!DoKeyExchange(std::bind(&Crypto::transport_dh_client, OurCrypto(), _1,
|
|
|
|
_2, _3, _4),
|
|
|
|
txKey, msg.N, remoteTransportPubKey,
|
|
|
|
parent->RouterEncryptionSecret()))
|
2018-09-08 15:53:20 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to mix keys for outbound session to ", remoteAddr);
|
2018-09-08 15:53:20 +00:00
|
|
|
Close();
|
2018-09-09 11:23:21 +00:00
|
|
|
return;
|
2018-09-08 15:53:20 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
Session::~Session()
|
2018-09-04 12:41:25 +00:00
|
|
|
{
|
2018-09-06 13:16:24 +00:00
|
|
|
if(sock)
|
|
|
|
{
|
|
|
|
utp_set_userdata(sock, nullptr);
|
2019-03-07 22:53:36 +00:00
|
|
|
sock = nullptr;
|
2018-09-06 13:16:24 +00:00
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
}
|
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
bool
|
|
|
|
Session::EncryptThenHash(const byte_t* ptr, uint32_t msgid, uint16_t length,
|
|
|
|
uint16_t remaining)
|
2018-09-06 11:46:19 +00:00
|
|
|
|
|
|
|
{
|
2018-09-08 15:53:20 +00:00
|
|
|
sendq.emplace_back();
|
|
|
|
auto& buf = sendq.back();
|
2018-09-12 13:29:42 +00:00
|
|
|
vecq.emplace_back();
|
2018-12-03 18:28:16 +00:00
|
|
|
auto& vec = vecq.back();
|
2019-01-02 01:04:04 +00:00
|
|
|
vec.iov_base = buf.data();
|
2018-12-03 18:28:16 +00:00
|
|
|
vec.iov_len = FragmentBufferSize;
|
2018-09-06 11:46:19 +00:00
|
|
|
buf.Randomize();
|
2019-01-02 01:04:06 +00:00
|
|
|
byte_t* noncePtr = buf.data() + FragmentHashSize;
|
|
|
|
byte_t* body = noncePtr + FragmentNonceSize;
|
|
|
|
byte_t* base = body;
|
|
|
|
AlignedBuffer< 24 > A(base);
|
2018-12-17 20:46:08 +00:00
|
|
|
// skip inner nonce
|
|
|
|
body += A.size();
|
|
|
|
// put msgid
|
|
|
|
htobe32buf(body, msgid);
|
2018-09-06 11:46:19 +00:00
|
|
|
body += sizeof(uint32_t);
|
2018-12-17 20:46:08 +00:00
|
|
|
// put length
|
|
|
|
htobe16buf(body, length);
|
|
|
|
body += sizeof(uint16_t);
|
|
|
|
// put remaining
|
|
|
|
htobe16buf(body, remaining);
|
|
|
|
body += sizeof(uint16_t);
|
|
|
|
// put body
|
|
|
|
memcpy(body, ptr, length);
|
2018-09-07 20:36:06 +00:00
|
|
|
|
2019-02-02 23:12:42 +00:00
|
|
|
llarp_buffer_t payload(base, base,
|
|
|
|
FragmentBufferSize - FragmentOverheadSize);
|
2018-09-07 20:36:06 +00:00
|
|
|
|
2019-01-02 01:04:06 +00:00
|
|
|
TunnelNonce nonce(noncePtr);
|
|
|
|
|
2018-09-07 20:36:06 +00:00
|
|
|
// encrypt
|
2019-02-11 19:45:42 +00:00
|
|
|
if(!OurCrypto()->xchacha20(payload, txKey, nonce))
|
2018-12-17 20:46:08 +00:00
|
|
|
return false;
|
2018-09-07 20:36:06 +00:00
|
|
|
|
2019-01-02 01:04:06 +00:00
|
|
|
payload.base = noncePtr;
|
2018-12-03 18:28:16 +00:00
|
|
|
payload.cur = payload.base;
|
|
|
|
payload.sz = FragmentBufferSize - FragmentHashSize;
|
2018-09-07 20:36:06 +00:00
|
|
|
// key'd hash
|
2019-02-11 19:45:42 +00:00
|
|
|
if(!OurCrypto()->hmac(buf.data(), payload, txKey))
|
2018-12-17 20:46:08 +00:00
|
|
|
return false;
|
2018-12-19 16:17:41 +00:00
|
|
|
return MutateKey(txKey, A);
|
2018-09-06 11:46:19 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
void
|
2018-12-17 20:46:08 +00:00
|
|
|
Session::EnterState(State st)
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2018-09-06 13:16:24 +00:00
|
|
|
state = st;
|
2018-11-21 17:46:33 +00:00
|
|
|
Alive();
|
2018-09-06 11:46:19 +00:00
|
|
|
if(st == eSessionReady)
|
|
|
|
{
|
2019-01-02 01:03:53 +00:00
|
|
|
parent->MapAddr(remoteRC.pubkey.as_array(), this);
|
2019-02-27 12:55:26 +00:00
|
|
|
if(!parent->SessionEstablished(this))
|
|
|
|
Close();
|
2018-09-06 11:46:19 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-02-15 22:19:19 +00:00
|
|
|
util::StatusObject
|
|
|
|
Session::ExtractStatus() const
|
|
|
|
{
|
2019-02-17 12:13:34 +00:00
|
|
|
return {{"client", !remoteRC.IsPublicRouter()},
|
|
|
|
{"sendBacklog", uint64_t(SendQueueBacklog())},
|
|
|
|
{"tx", m_TXRate},
|
|
|
|
{"rx", m_RXRate},
|
|
|
|
{"remoteAddr", remoteAddr.ToString()},
|
|
|
|
{"pubkey", remoteRC.pubkey.ToHex()}};
|
2019-02-15 22:19:19 +00:00
|
|
|
}
|
|
|
|
|
2018-12-19 16:17:41 +00:00
|
|
|
bool
|
|
|
|
Session::GotSessionRenegotiate(const LinkIntroMessage* msg)
|
|
|
|
{
|
|
|
|
// check with parent and possibly process and store new rc
|
|
|
|
if(!parent->SessionRenegotiate(msg->rc, remoteRC))
|
|
|
|
{
|
|
|
|
// failed to renegotiate
|
|
|
|
Close();
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
// set remote rc
|
|
|
|
remoteRC = msg->rc;
|
2019-02-02 23:12:42 +00:00
|
|
|
// recalculate rx key
|
2019-01-26 15:40:58 +00:00
|
|
|
return DoKeyExchange(
|
2019-02-11 19:45:42 +00:00
|
|
|
std::bind(&Crypto::transport_dh_server, OurCrypto(), _1, _2, _3, _4),
|
2019-01-26 15:40:58 +00:00
|
|
|
rxKey, msg->N, remoteRC.enckey, parent->RouterEncryptionSecret());
|
2018-12-19 16:17:41 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
bool
|
2019-04-02 09:03:53 +00:00
|
|
|
Session::RenegotiateSession()
|
2018-12-19 16:17:41 +00:00
|
|
|
{
|
|
|
|
LinkIntroMessage lim;
|
|
|
|
lim.rc = parent->GetOurRC();
|
|
|
|
lim.N.Randomize();
|
|
|
|
lim.P = 60 * 1000 * 10;
|
|
|
|
if(!lim.Sign(parent->Sign))
|
|
|
|
return false;
|
2019-02-02 23:12:42 +00:00
|
|
|
|
|
|
|
std::array< byte_t, LinkIntroMessage::MaxSize > tmp;
|
|
|
|
llarp_buffer_t buf(tmp);
|
2018-12-19 16:17:41 +00:00
|
|
|
if(!lim.BEncode(&buf))
|
|
|
|
return false;
|
|
|
|
// rewind and resize buffer
|
|
|
|
buf.sz = buf.cur - buf.base;
|
|
|
|
buf.cur = buf.base;
|
|
|
|
// send message
|
|
|
|
if(!SendMessageBuffer(buf))
|
|
|
|
return false;
|
|
|
|
// regen our tx Key
|
2019-01-26 15:40:58 +00:00
|
|
|
return DoKeyExchange(
|
2019-02-11 19:45:42 +00:00
|
|
|
std::bind(&Crypto::transport_dh_client, OurCrypto(), _1, _2, _3, _4),
|
2019-01-26 15:40:58 +00:00
|
|
|
txKey, lim.N, remoteRC.enckey, parent->RouterEncryptionSecret());
|
2018-12-19 16:17:41 +00:00
|
|
|
}
|
|
|
|
|
2018-09-06 11:46:19 +00:00
|
|
|
bool
|
2018-12-17 22:43:16 +00:00
|
|
|
Session::VerifyThenDecrypt(const byte_t* ptr)
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("verify then decrypt ", remoteAddr);
|
2018-09-06 11:46:19 +00:00
|
|
|
ShortHash digest;
|
2018-09-06 20:31:58 +00:00
|
|
|
|
2019-02-02 23:12:42 +00:00
|
|
|
llarp_buffer_t hbuf(ptr + FragmentHashSize,
|
|
|
|
FragmentBufferSize - FragmentHashSize);
|
2019-02-11 19:45:42 +00:00
|
|
|
if(!OurCrypto()->hmac(digest.data(), hbuf, rxKey))
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("keyed hash failed");
|
2018-09-06 11:46:19 +00:00
|
|
|
return false;
|
|
|
|
}
|
2019-04-17 14:46:00 +00:00
|
|
|
const ShortHash expected(ptr);
|
2018-09-07 17:41:49 +00:00
|
|
|
if(expected != digest)
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("Message Integrity Failed: got ", digest, " from ", remoteAddr,
|
|
|
|
" instead of ", expected);
|
2018-12-19 17:48:29 +00:00
|
|
|
Close();
|
2018-09-06 11:46:19 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2019-02-02 23:12:42 +00:00
|
|
|
llarp_buffer_t in(ptr + FragmentOverheadSize,
|
|
|
|
FragmentBufferSize - FragmentOverheadSize);
|
2018-12-16 20:34:04 +00:00
|
|
|
|
2019-02-03 00:31:10 +00:00
|
|
|
llarp_buffer_t out(rxFragBody);
|
2018-12-16 20:34:04 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
// decrypt
|
2019-02-11 19:45:42 +00:00
|
|
|
if(!OurCrypto()->xchacha20_alt(out, in, rxKey, ptr + FragmentHashSize))
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to decrypt message from ", remoteAddr);
|
2018-12-17 20:46:08 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
// get inner nonce
|
2019-01-02 01:04:06 +00:00
|
|
|
AlignedBuffer< 24 > A(out.base);
|
2018-12-17 20:46:08 +00:00
|
|
|
// advance buffer
|
|
|
|
out.cur += A.size();
|
|
|
|
// read msgid
|
2018-12-16 20:34:04 +00:00
|
|
|
uint32_t msgid;
|
2019-02-17 12:13:34 +00:00
|
|
|
if(!out.read_uint32(msgid))
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to read msgid");
|
2018-12-16 20:34:04 +00:00
|
|
|
return false;
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
|
|
|
// read length and remaining
|
|
|
|
uint16_t length, remaining;
|
2019-02-17 12:13:34 +00:00
|
|
|
if(!(out.read_uint16(length) && out.read_uint16(remaining)))
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to read the rest of the header");
|
2018-09-06 11:46:19 +00:00
|
|
|
return false;
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2019-02-05 00:41:33 +00:00
|
|
|
if(length > (out.sz - (out.cur - out.base)))
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2018-12-16 20:34:04 +00:00
|
|
|
// too big length
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("fragment body too big");
|
2018-09-06 11:46:19 +00:00
|
|
|
return false;
|
|
|
|
}
|
2018-12-17 22:43:16 +00:00
|
|
|
if(msgid < m_NextRXMsgID)
|
|
|
|
return false;
|
|
|
|
m_NextRXMsgID = msgid;
|
2018-12-16 20:34:04 +00:00
|
|
|
|
2018-12-17 20:46:08 +00:00
|
|
|
// get message
|
2018-12-17 22:43:16 +00:00
|
|
|
if(m_RecvMsgs.find(msgid) == m_RecvMsgs.end())
|
2019-01-26 15:40:58 +00:00
|
|
|
{
|
2019-02-05 00:43:37 +00:00
|
|
|
m_RecvMsgs.emplace(msgid, InboundMessage{});
|
2019-01-26 15:40:58 +00:00
|
|
|
}
|
2018-12-17 22:43:16 +00:00
|
|
|
|
|
|
|
auto itr = m_RecvMsgs.find(msgid);
|
2018-12-17 20:46:08 +00:00
|
|
|
// add message activity
|
2018-12-17 22:43:16 +00:00
|
|
|
itr->second.lastActive = parent->Now();
|
2018-12-17 20:46:08 +00:00
|
|
|
// append data
|
2018-12-17 22:43:16 +00:00
|
|
|
if(!itr->second.AppendData(out.cur, length))
|
2018-12-17 20:46:08 +00:00
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("inbound buffer is full");
|
2018-12-17 20:46:08 +00:00
|
|
|
return false; // not enough room
|
|
|
|
}
|
2018-12-19 16:17:41 +00:00
|
|
|
// mutate key
|
|
|
|
if(!MutateKey(rxKey, A))
|
|
|
|
{
|
2019-02-11 19:45:42 +00:00
|
|
|
LogError("failed to mutate rx key");
|
2018-12-19 16:17:41 +00:00
|
|
|
return false;
|
|
|
|
}
|
2019-01-02 01:03:53 +00:00
|
|
|
|
2018-12-16 20:34:04 +00:00
|
|
|
if(remaining == 0)
|
2018-09-06 11:46:19 +00:00
|
|
|
{
|
2018-12-27 19:10:38 +00:00
|
|
|
// we done with this guy, prune next tick
|
|
|
|
itr->second.lastActive = 0;
|
2019-02-03 00:48:10 +00:00
|
|
|
ManagedBuffer buf(itr->second.buffer);
|
2018-12-17 20:46:08 +00:00
|
|
|
// resize
|
2019-02-02 23:12:42 +00:00
|
|
|
buf.underlying.sz = buf.underlying.cur - buf.underlying.base;
|
2018-12-16 20:34:04 +00:00
|
|
|
// rewind
|
2019-02-02 23:12:42 +00:00
|
|
|
buf.underlying.cur = buf.underlying.base;
|
2018-12-17 20:46:08 +00:00
|
|
|
// process buffer
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("got message ", msgid, " from ", remoteAddr);
|
2019-02-23 17:54:35 +00:00
|
|
|
parent->HandleMessage(this, buf.underlying);
|
2018-12-17 20:46:08 +00:00
|
|
|
}
|
2018-12-27 19:10:38 +00:00
|
|
|
return true;
|
2018-09-06 11:46:19 +00:00
|
|
|
}
|
|
|
|
|
2018-09-06 20:31:58 +00:00
|
|
|
void
|
2018-12-17 20:46:08 +00:00
|
|
|
Session::Close()
|
2018-09-06 20:31:58 +00:00
|
|
|
{
|
|
|
|
if(state != eClose)
|
|
|
|
{
|
2018-09-07 20:36:06 +00:00
|
|
|
if(sock)
|
|
|
|
{
|
2019-01-07 16:13:16 +00:00
|
|
|
if(state == eLinkEstablished || state == eSessionReady)
|
|
|
|
{
|
2019-01-07 16:35:25 +00:00
|
|
|
// only call shutdown and close when we are actually connected
|
2019-01-07 16:13:16 +00:00
|
|
|
utp_shutdown(sock, SHUT_RDWR);
|
2019-01-07 16:35:25 +00:00
|
|
|
utp_close(sock);
|
2019-01-07 16:13:16 +00:00
|
|
|
}
|
2019-02-11 19:45:42 +00:00
|
|
|
LogDebug("utp_close ", remoteAddr);
|
2018-09-07 20:36:06 +00:00
|
|
|
}
|
2018-09-06 20:31:58 +00:00
|
|
|
}
|
|
|
|
EnterState(eClose);
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
2018-12-17 20:46:08 +00:00
|
|
|
Session::Alive()
|
2018-09-06 20:31:58 +00:00
|
|
|
{
|
2018-12-17 20:46:08 +00:00
|
|
|
lastActive = parent->Now();
|
2018-09-06 11:46:19 +00:00
|
|
|
}
|
2019-04-02 09:03:53 +00:00
|
|
|
|
|
|
|
InboundSession::InboundSession(LinkLayer* p, utp_socket* s,
|
|
|
|
const Addr& addr)
|
|
|
|
: Session(p)
|
|
|
|
{
|
|
|
|
sock = s;
|
|
|
|
remoteAddr = addr;
|
|
|
|
RouterID rid = p->GetOurRC().pubkey;
|
|
|
|
OurCrypto()->shorthash(rxKey, llarp_buffer_t(rid));
|
|
|
|
remoteRC.Clear();
|
|
|
|
|
2019-04-28 15:57:41 +00:00
|
|
|
ABSL_ATTRIBUTE_UNUSED void* res = utp_set_userdata(sock, this);
|
|
|
|
assert(res == this);
|
2019-04-02 09:03:53 +00:00
|
|
|
assert(s == sock);
|
|
|
|
GotLIM = std::bind(&InboundSession::InboundLIM, this, _1);
|
|
|
|
}
|
|
|
|
|
|
|
|
bool
|
|
|
|
InboundSession::InboundLIM(const LinkIntroMessage* msg)
|
|
|
|
{
|
|
|
|
if(gotLIM && remoteRC.pubkey != msg->rc.pubkey)
|
|
|
|
{
|
|
|
|
Close();
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
if(!gotLIM)
|
|
|
|
{
|
|
|
|
remoteRC = msg->rc;
|
|
|
|
OurCrypto()->shorthash(txKey, llarp_buffer_t(remoteRC.pubkey));
|
|
|
|
|
|
|
|
if(!DoKeyExchange(std::bind(&Crypto::transport_dh_server, OurCrypto(),
|
|
|
|
_1, _2, _3, _4),
|
|
|
|
rxKey, msg->N, remoteRC.enckey,
|
|
|
|
parent->TransportSecretKey()))
|
|
|
|
return false;
|
|
|
|
|
|
|
|
std::array< byte_t, LinkIntroMessage::MaxSize > tmp;
|
|
|
|
llarp_buffer_t buf(tmp);
|
|
|
|
LinkIntroMessage replymsg;
|
|
|
|
replymsg.rc = parent->GetOurRC();
|
|
|
|
if(!replymsg.rc.Verify(OurCrypto(), parent->Now()))
|
|
|
|
{
|
|
|
|
LogError("our RC is invalid? closing session to", remoteAddr);
|
|
|
|
Close();
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
replymsg.N.Randomize();
|
|
|
|
replymsg.P = DefaultLinkSessionLifetime;
|
|
|
|
if(!replymsg.Sign(parent->Sign))
|
|
|
|
{
|
|
|
|
LogError("failed to sign LIM for inbound handshake from ",
|
|
|
|
remoteAddr);
|
|
|
|
Close();
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
// encode
|
|
|
|
if(!replymsg.BEncode(&buf))
|
|
|
|
{
|
|
|
|
LogError("failed to encode LIM for handshake from ", remoteAddr);
|
|
|
|
Close();
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
// rewind
|
|
|
|
buf.sz = buf.cur - buf.base;
|
|
|
|
buf.cur = buf.base;
|
|
|
|
// send
|
|
|
|
if(!SendMessageBuffer(buf))
|
|
|
|
{
|
|
|
|
LogError("failed to repl to handshake from ", remoteAddr);
|
|
|
|
Close();
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
if(!DoKeyExchange(std::bind(&Crypto::transport_dh_client, OurCrypto(),
|
|
|
|
_1, _2, _3, _4),
|
|
|
|
txKey, replymsg.N, remoteRC.enckey,
|
|
|
|
parent->RouterEncryptionSecret()))
|
|
|
|
|
|
|
|
return false;
|
|
|
|
LogDebug("Sent reply LIM");
|
|
|
|
gotLIM = true;
|
|
|
|
EnterState(eSessionReady);
|
|
|
|
/// future LIM are used for session renegotiation
|
|
|
|
GotLIM = std::bind(&Session::GotSessionRenegotiate, this, _1);
|
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
OutboundSession::OutboundSession(LinkLayer* p, utp_socket* s,
|
|
|
|
const RouterContact& rc,
|
|
|
|
const AddressInfo& addr)
|
|
|
|
: Session(p)
|
|
|
|
{
|
|
|
|
remoteTransportPubKey = addr.pubkey;
|
|
|
|
remoteRC = rc;
|
|
|
|
sock = s;
|
|
|
|
remoteAddr = addr;
|
|
|
|
|
|
|
|
RouterID rid = remoteRC.pubkey;
|
|
|
|
OurCrypto()->shorthash(txKey, llarp_buffer_t(rid));
|
|
|
|
rid = p->GetOurRC().pubkey;
|
|
|
|
OurCrypto()->shorthash(rxKey, llarp_buffer_t(rid));
|
|
|
|
|
2019-04-28 15:57:41 +00:00
|
|
|
ABSL_ATTRIBUTE_UNUSED void* res = utp_set_userdata(sock, this);
|
|
|
|
assert(res == this);
|
2019-04-02 09:03:53 +00:00
|
|
|
assert(s == sock);
|
|
|
|
|
|
|
|
GotLIM = std::bind(&OutboundSession::OutboundLIM, this, _1);
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
OutboundSession::Start()
|
|
|
|
{
|
|
|
|
utp_connect(sock, remoteAddr, remoteAddr.SockLen());
|
|
|
|
EnterState(eConnecting);
|
|
|
|
}
|
|
|
|
|
|
|
|
bool
|
|
|
|
OutboundSession::OutboundLIM(const LinkIntroMessage* msg)
|
|
|
|
{
|
|
|
|
if(gotLIM && remoteRC.pubkey != msg->rc.pubkey)
|
|
|
|
{
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
remoteRC = msg->rc;
|
|
|
|
gotLIM = true;
|
|
|
|
|
|
|
|
if(!DoKeyExchange(std::bind(&Crypto::transport_dh_server, OurCrypto(), _1,
|
|
|
|
_2, _3, _4),
|
|
|
|
rxKey, msg->N, remoteRC.enckey,
|
|
|
|
parent->RouterEncryptionSecret()))
|
|
|
|
{
|
|
|
|
Close();
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
/// future LIM are used for session renegotiation
|
|
|
|
GotLIM = std::bind(&Session::GotSessionRenegotiate, this, _1);
|
|
|
|
EnterState(eSessionReady);
|
|
|
|
return true;
|
|
|
|
}
|
2018-09-04 12:41:25 +00:00
|
|
|
} // namespace utp
|
|
|
|
} // namespace llarp
|