mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-07 14:09:07 +02:00
Skip default port send in signal proto
This commit is contained in:
@@ -94,7 +94,8 @@ type PQHandshaker interface {
|
|||||||
// peer-config time (the pull path). ok is false until one has been derived.
|
// peer-config time (the pull path). ok is false until one has been derived.
|
||||||
PSK(remoteKey string) (wgtypes.Key, bool)
|
PSK(remoteKey string) (wgtypes.Key, bool)
|
||||||
// SetRemoteAddr registers the peer's data-path endpoint learned from signalling:
|
// SetRemoteAddr registers the peer's data-path endpoint learned from signalling:
|
||||||
// its WG overlay IP with the advertised pq UDP port.
|
// its WG overlay IP with the announced pq UDP port (port 0 means the peer omitted
|
||||||
|
// it and is on the default port).
|
||||||
SetRemoteAddr(remoteKey string, addr netip.AddrPort)
|
SetRemoteAddr(remoteKey string, addr netip.AddrPort)
|
||||||
// OnDataPathRekeyed signals a fresh WireGuard handshake for the peer; it clocks the
|
// OnDataPathRekeyed signals a fresh WireGuard handshake for the peer; it clocks the
|
||||||
// next chained PSK rotation pushed over the data path. sinceActivity is how long
|
// next chained PSK rotation pushed over the data path. sinceActivity is how long
|
||||||
|
|||||||
@@ -182,9 +182,11 @@ func (h *Handshaker) Listen(ctx context.Context) {
|
|||||||
// pqRegisterEndpoint feeds the post-quantum handshaker the peer's data-path endpoint
|
// pqRegisterEndpoint feeds the post-quantum handshaker the peer's data-path endpoint
|
||||||
// (its WG overlay IP plus the advertised pq UDP port) learned from a remote offer/answer.
|
// (its WG overlay IP plus the advertised pq UDP port) learned from a remote offer/answer.
|
||||||
func (h *Handshaker) pqRegisterEndpoint(remotePort int) {
|
func (h *Handshaker) pqRegisterEndpoint(remotePort int) {
|
||||||
if h.config.PQ == nil || remotePort <= 0 || remotePort > 65535 || len(h.config.WgConfig.AllowedIps) == 0 {
|
if h.config.PQ == nil || remotePort < 0 || remotePort > 65535 || len(h.config.WgConfig.AllowedIps) == 0 {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
// remotePort may be 0 (the peer omitted it, meaning the default port); the adapter
|
||||||
|
// resolves 0 to DefaultPort.
|
||||||
addr := netip.AddrPortFrom(h.config.WgConfig.AllowedIps[0].Addr(), uint16(remotePort))
|
addr := netip.AddrPortFrom(h.config.WgConfig.AllowedIps[0].Addr(), uint16(remotePort))
|
||||||
h.config.PQ.SetRemoteAddr(h.config.Key, addr)
|
h.config.PQ.SetRemoteAddr(h.config.Key, addr)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -186,8 +186,9 @@ func (m *Manager) trace(msg string, args ...any) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// AddPeer registers where a peer's data-path messages are sent and received: its
|
// AddPeer registers where a peer's data-path messages are sent and received: its
|
||||||
// overlay endpoint (IP:port). A peer that advertises a PQ endpoint is, by that fact,
|
// overlay endpoint (IP:port). This is pure routing and says nothing about capability —
|
||||||
// running the KEM, so it is marked capable.
|
// PQ capability is decided solely from the peer's KEM payload (see processOffer /
|
||||||
|
// processAnswer / MarkNonCapable), never from an endpoint or port.
|
||||||
func (m *Manager) AddPeer(remoteID RemoteID, endpoint netip.AddrPort) {
|
func (m *Manager) AddPeer(remoteID RemoteID, endpoint netip.AddrPort) {
|
||||||
if !endpoint.IsValid() {
|
if !endpoint.IsValid() {
|
||||||
return
|
return
|
||||||
@@ -198,7 +199,6 @@ func (m *Manager) AddPeer(remoteID RemoteID, endpoint netip.AddrPort) {
|
|||||||
}
|
}
|
||||||
m.peerAddrs[remoteID] = endpoint
|
m.peerAddrs[remoteID] = endpoint
|
||||||
m.peersByAddr[endpoint] = remoteID
|
m.peersByAddr[endpoint] = remoteID
|
||||||
m.capable[remoteID] = true
|
|
||||||
m.mu.Unlock()
|
m.mu.Unlock()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -54,12 +54,22 @@ type pqHandshaker struct {
|
|||||||
mgr *pqkem.Manager
|
mgr *pqkem.Manager
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// announcedPort is the PQ data-path port to advertise to peers. It is omitted (0) when
|
||||||
|
// the manager is on DefaultPort, since peers assume the default when no port is sent;
|
||||||
|
// only a non-default (collision-forced) port is announced explicitly.
|
||||||
|
func (p pqHandshaker) announcedPort() int {
|
||||||
|
if port := p.mgr.LocalPort(); port != DefaultPort {
|
||||||
|
return port
|
||||||
|
}
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
func (p pqHandshaker) OfferPayload(remoteKey string) ([]byte, int) {
|
func (p pqHandshaker) OfferPayload(remoteKey string) ([]byte, int) {
|
||||||
payload, err := p.mgr.SignalOffer(pqkem.RemoteID(remoteKey))
|
payload, err := p.mgr.SignalOffer(pqkem.RemoteID(remoteKey))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Warnf("pqkem: build offer for %s: %v", remoteKey, err)
|
log.Warnf("pqkem: build offer for %s: %v", remoteKey, err)
|
||||||
}
|
}
|
||||||
return payload, p.mgr.LocalPort()
|
return payload, p.announcedPort()
|
||||||
}
|
}
|
||||||
|
|
||||||
func (p pqHandshaker) AnswerPayload(remoteKey string, recvOffer []byte) ([]byte, int) {
|
func (p pqHandshaker) AnswerPayload(remoteKey string, recvOffer []byte) ([]byte, int) {
|
||||||
@@ -72,13 +82,13 @@ func (p pqHandshaker) AnswerPayload(remoteKey string, recvOffer []byte) ([]byte,
|
|||||||
if !p.mgr.IsInitiator(pqkem.RemoteID(remoteKey)) {
|
if !p.mgr.IsInitiator(pqkem.RemoteID(remoteKey)) {
|
||||||
p.mgr.MarkNonCapable(pqkem.RemoteID(remoteKey))
|
p.mgr.MarkNonCapable(pqkem.RemoteID(remoteKey))
|
||||||
}
|
}
|
||||||
return nil, p.mgr.LocalPort()
|
return nil, p.announcedPort()
|
||||||
}
|
}
|
||||||
payload, err := p.mgr.SignalOnOffer(pqkem.RemoteID(remoteKey), recvOffer)
|
payload, err := p.mgr.SignalOnOffer(pqkem.RemoteID(remoteKey), recvOffer)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Warnf("pqkem: build answer for %s: %v", remoteKey, err)
|
log.Warnf("pqkem: build answer for %s: %v", remoteKey, err)
|
||||||
}
|
}
|
||||||
return payload, p.mgr.LocalPort()
|
return payload, p.announcedPort()
|
||||||
}
|
}
|
||||||
|
|
||||||
func (p pqHandshaker) OnAnswer(remoteKey string, recvAnswer []byte) {
|
func (p pqHandshaker) OnAnswer(remoteKey string, recvAnswer []byte) {
|
||||||
@@ -107,14 +117,20 @@ func (p pqHandshaker) PSK(remoteKey string) (wgtypes.Key, bool) {
|
|||||||
return wgtypes.Key(psk), true
|
return wgtypes.Key(psk), true
|
||||||
}
|
}
|
||||||
|
|
||||||
// SetRemoteAddr registers the peer's data-path endpoint (overlay IP + pq UDP port)
|
// SetRemoteAddr registers the peer's data-path endpoint learned from signalling. A
|
||||||
// learned from signalling. Sends only ever fire once the tunnel is up (clocked by
|
// zero port means the peer omitted it (it is on DefaultPort), so we resolve it here —
|
||||||
// OnDataPathRekeyed), so registering here is safe even before connection-up.
|
// DefaultPort lives in this package, not in peer. Sends only ever fire once the tunnel
|
||||||
|
// is up (clocked by OnDataPathRekeyed), so registering here is safe even before
|
||||||
|
// connection-up.
|
||||||
func (p pqHandshaker) SetRemoteAddr(remoteKey string, addr netip.AddrPort) {
|
func (p pqHandshaker) SetRemoteAddr(remoteKey string, addr netip.AddrPort) {
|
||||||
if !addr.IsValid() || addr.Port() == 0 {
|
if !addr.Addr().IsValid() {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
p.mgr.AddPeer(pqkem.RemoteID(remoteKey), addr)
|
port := addr.Port()
|
||||||
|
if port == 0 {
|
||||||
|
port = DefaultPort
|
||||||
|
}
|
||||||
|
p.mgr.AddPeer(pqkem.RemoteID(remoteKey), netip.AddrPortFrom(addr.Addr(), port))
|
||||||
}
|
}
|
||||||
|
|
||||||
// OnDataPathRekeyed clocks the next chained PSK rotation on a fresh WG handshake.
|
// OnDataPathRekeyed clocks the next chained PSK rotation on a fresh WG handshake.
|
||||||
|
|||||||
Reference in New Issue
Block a user