Bind test

This commit is contained in:
braginini
2022-09-04 22:52:52 +02:00
parent 4e5ee70b3d
commit f5e974c04c
7 changed files with 310 additions and 16 deletions
+152
View File
@@ -0,0 +1,152 @@
package iface
import (
log "github.com/sirupsen/logrus"
"golang.zx2c4.com/wireguard/conn"
"net"
"net/netip"
"sync"
)
type packets struct {
buff []byte
addr net.UDPAddr
}
type ICEBind struct {
mu sync.Mutex
packets chan packets
closeSignal chan struct{}
conn *net.UDPConn
}
func NewICEBind(udpConn *net.UDPConn) *ICEBind {
return &ICEBind{
conn: udpConn,
mu: sync.Mutex{},
}
}
func (bind *ICEBind) Open(port uint16) ([]conn.ReceiveFunc, uint16, error) {
bind.mu.Lock()
defer bind.mu.Unlock()
log.Infof("opening Bind on port %d", port)
udpConn, p, err := listenNet("udp4", int(port))
if err != nil {
return nil, 0, err
}
bind.conn = udpConn
return []conn.ReceiveFunc{bind.makeReceiveIPv4(udpConn)}, uint16(p), nil
/*bind.packets = make(chan packets)
bind.closeSignal = make(chan struct{})
addrPort, err := netip.ParseAddrPort(bind.conn.LocalAddr().String())
if err != nil {
return nil, 0, err
}
return []conn.ReceiveFunc{bind.makeReceiveIPv4(bind.conn)}, addrPort.Port(), nil*/
}
func (bind *ICEBind) fakeReceiveIPv4(c *net.UDPConn) conn.ReceiveFunc {
return func(buff []byte) (int, conn.Endpoint, error) {
return 0, nil, nil
}
}
func (bind *ICEBind) makeReceiveIPv4(c *net.UDPConn) conn.ReceiveFunc {
return func(buff []byte) (int, conn.Endpoint, error) {
n, endpoint, err := c.ReadFromUDP(buff)
if endpoint != nil {
endpoint.IP = endpoint.IP.To4()
}
return n, (*conn.StdNetEndpoint)(endpoint), err
}
}
/*func (bind *ICEBind) receive(buff []byte) (int, conn.Endpoint, error) {
n, endpoint, err := bind.conn.ReadFromUDP(buff)
if endpoint != nil {
endpoint.IP = endpoint.IP.To4()
}
return n, (*conn.StdNetEndpoint)(endpoint), err
select {
case <-bind.closeSignal:
return 0, nil, net.ErrClosed
case pkt := <-bind.packets:
return copy(buf, pkt.buff), (*conn.StdNetEndpoint)(&pkt.addr), nil
}
}*/
func (bind *ICEBind) Close() error {
bind.mu.Lock()
defer bind.mu.Unlock()
err := bind.conn.Close()
if err != nil {
return err
}
if bind.closeSignal != nil {
select {
case <-bind.closeSignal:
default:
close(bind.closeSignal)
}
bind.packets = nil
}
return nil
}
// SetMark sets the mark for each packet sent through this Bind.
// This mark is passed to the kernel as the socket option SO_MARK.
func (bind *ICEBind) SetMark(mark uint32) error {
return nil
}
func (bind *ICEBind) Send(buf []byte, endpoint conn.Endpoint) error {
nend, ok := endpoint.(*conn.StdNetEndpoint)
if !ok {
return conn.ErrWrongEndpointType
}
_, err := bind.conn.WriteToUDP(buf, (*net.UDPAddr)(nend))
return err
}
// ParseEndpoint creates a new endpoint from a string.
func (bind *ICEBind) ParseEndpoint(s string) (ep conn.Endpoint, err error) {
ap, err := netip.ParseAddrPort(s)
if err != nil {
return nil, err
}
return (*conn.StdNetEndpoint)(&net.UDPAddr{
IP: ap.Addr().AsSlice(),
Port: int(ap.Port()),
Zone: ap.Addr().Zone(),
}), err
}
func listenNet(network string, port int) (*net.UDPConn, int, error) {
conn, err := net.ListenUDP(network, &net.UDPAddr{Port: port})
if err != nil {
return nil, 0, err
}
// Retrieve port.
laddr := conn.LocalAddr()
uaddr, err := net.ResolveUDPAddr(
laddr.Network(),
laddr.String(),
)
if err != nil {
return nil, 0, err
}
return conn, uaddr.Port, nil
}
+8 -7
View File
@@ -3,6 +3,7 @@ package iface
import (
"errors"
"math"
"net"
"os"
"syscall"
@@ -32,6 +33,12 @@ func WireguardModExists() bool {
return errors.Is(err, syscall.EINVAL)
}
func (w *WGIface) CreateNew(sharedSock *net.UDPConn) error {
w.mu.Lock()
defer w.mu.Unlock()
return w.createWithUserspaceNew(sharedSock)
}
// Create creates a new Wireguard interface, sets a given IP and brings it up.
// Will reuse an existing one.
@@ -39,13 +46,7 @@ func (w *WGIface) Create() error {
w.mu.Lock()
defer w.mu.Unlock()
if WireguardModExists() {
log.Info("using kernel WireGuard")
return w.createWithKernel()
} else {
log.Info("using userspace WireGuard")
return w.createWithUserspace()
}
return w.createWithUserspace()
}
// createWithKernel Creates a new Wireguard interface using kernel Wireguard module.
+42
View File
@@ -12,6 +12,48 @@ import (
"net"
)
func (w *WGIface) createWithUserspaceNew(sharedSock *net.UDPConn) error {
tunIface, err := tun.CreateTUN(w.Name, w.MTU)
if err != nil {
return err
}
w.Interface = tunIface
bind := &ICEBind{
conn: sharedSock,
}
// We need to create a wireguard-go device and listen to configuration requests
tunDevice := device.NewDevice(tunIface, bind, device.NewLogger(device.LogLevelSilent, "[wiretrustee] "))
err = tunDevice.Up()
if err != nil {
return err
}
uapi, err := getUAPI(w.Name)
if err != nil {
return err
}
go func() {
for {
uapiConn, uapiErr := uapi.Accept()
if uapiErr != nil {
log.Traceln("uapi Accept failed with error: ", uapiErr)
continue
}
go tunDevice.IpcHandle(uapiConn)
}
}()
log.Debugln("UAPI listener started")
err = w.assignAddr()
if err != nil {
return err
}
return nil
}
// createWithUserspace Creates a new Wireguard interface, using wireguard-go userspace implementation
func (w *WGIface) createWithUserspace() error {