From 132d38925daddc61e933557b0f3b838a4f0f0c12 Mon Sep 17 00:00:00 2001 From: Owen Date: Fri, 31 Jul 2026 16:23:49 -0400 Subject: [PATCH] Add alias when connecting to exit node --- olm/exitnode.go | 28 ++++++++++++++++++++++++++++ olm/types.go | 13 +++++++------ 2 files changed, 35 insertions(+), 6 deletions(-) diff --git a/olm/exitnode.go b/olm/exitnode.go index 0dd1b5e..37dc9a9 100644 --- a/olm/exitnode.go +++ b/olm/exitnode.go @@ -3,6 +3,7 @@ package olm import ( "encoding/json" "fmt" + "net" "strings" "github.com/fosrl/newt/logger" @@ -12,6 +13,12 @@ import ( "github.com/fosrl/olm/websocket" ) +// exitNodeAliasSiteId is the sentinel siteId used when registering exit node +// aliases with the DNS proxy. It is not a real site, and the JIT handler +// treats siteId 0 as "no JIT lookup", which is correct here since the exit +// node is connected directly rather than on demand. +const exitNodeAliasSiteId = 0 + // connectExitNode configures a WireGuard peer connection to an exit node, on the // same interface and WireGuard device already used for site peers. The exit node // lives in a different address space than the site tunnel, so a secondary address @@ -87,6 +94,18 @@ persistent_keepalive_interval=%d`, util.FixKey(cfg.PublicKey), allowedIP, resolv cfgCopy := cfg o.exitNode = &cfgCopy + if o.dnsProxy != nil { + serverIP := net.ParseIP(cfg.ServerIP) + if serverIP != nil { + for _, alias := range cfg.Aliases { + logger.Debug("Adding alias %s to the edit node", alias) + if err := o.dnsProxy.AddDNSRecord(alias, serverIP, exitNodeAliasSiteId); err != nil { + logger.Warn("Failed to add DNS record for exit node alias %s: %v", alias, err) + } + } + } + } + logger.Info("Connected to exit node at %s", resolvedEndpoint) return nil } @@ -108,6 +127,15 @@ func (o *Olm) removeExitNodePeerLocked() error { cfg := o.exitNode o.exitNode = nil + if o.dnsProxy != nil { + serverIP := net.ParseIP(cfg.ServerIP) + if serverIP != nil { + for _, alias := range cfg.Aliases { + o.dnsProxy.RemoveDNSRecordForSite(alias, serverIP, exitNodeAliasSiteId) + } + } + } + if o.dev != nil { if err := peers.RemovePeer(o.dev, 0, cfg.PublicKey); err != nil { logger.Warn("Failed to remove exit node peer: %v", err) diff --git a/olm/types.go b/olm/types.go index 379794d..98c1d35 100644 --- a/olm/types.go +++ b/olm/types.go @@ -21,12 +21,13 @@ type WgData struct { // also be sent later via "olm/wg/exitnode/connect" / "olm/wg/exitnode/disconnect" // so the server can direct a client to connect/disconnect after registration. type ExitNodeConfig struct { - Connect bool `json:"connect"` - Endpoint string `json:"endpoint"` - RelayPort uint16 `json:"relayPort"` - PublicKey string `json:"publicKey"` - ServerIP string `json:"serverIP"` - TunnelIP string `json:"tunnelIP"` + Connect bool `json:"connect"` + Endpoint string `json:"endpoint"` + RelayPort uint16 `json:"relayPort"` + PublicKey string `json:"publicKey"` + ServerIP string `json:"serverIP"` + TunnelIP string `json:"tunnelIP"` + Aliases []string `json:"aliases,omitempty"` } type SyncData struct {