vpn.go 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324
  1. /*
  2. Copyright © 2021-2022 Ettore Di Giacinto <[email protected]>
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package vpn
  14. import (
  15. "context"
  16. "fmt"
  17. "io"
  18. "net"
  19. "os"
  20. "runtime"
  21. "sync"
  22. "time"
  23. "github.com/ipfs/go-log"
  24. "github.com/libp2p/go-libp2p/core/network"
  25. "github.com/libp2p/go-libp2p/core/peer"
  26. "github.com/google/gopacket"
  27. "github.com/google/gopacket/layers"
  28. "github.com/mudler/edgevpn/internal"
  29. "github.com/mudler/edgevpn/pkg/blockchain"
  30. "github.com/mudler/edgevpn/pkg/logger"
  31. "github.com/mudler/edgevpn/pkg/node"
  32. "github.com/mudler/edgevpn/pkg/protocol"
  33. "github.com/mudler/edgevpn/pkg/stream"
  34. "github.com/mudler/edgevpn/pkg/types"
  35. "github.com/mudler/water"
  36. "github.com/pkg/errors"
  37. "github.com/songgao/packets/ethernet"
  38. )
  39. type streamManager interface {
  40. Connected(n network.Network, c network.Stream)
  41. Disconnected(n network.Network, c network.Stream)
  42. HasStream(n network.Network, pid peer.ID) (network.Stream, error)
  43. Close() error
  44. }
  45. func VPNNetworkService(p ...Option) node.NetworkService {
  46. return func(ctx context.Context, nc node.Config, n *node.Node, b *blockchain.Ledger) error {
  47. c := &Config{
  48. Concurrency: 1,
  49. LedgerAnnounceTime: 5 * time.Second,
  50. Timeout: 15 * time.Second,
  51. Logger: logger.New(log.LevelDebug),
  52. MaxStreams: 30,
  53. }
  54. if err := c.Apply(p...); err != nil {
  55. return err
  56. }
  57. ifce, err := createInterface(c)
  58. if err != nil {
  59. return err
  60. }
  61. defer ifce.Close()
  62. var mgr streamManager
  63. if c.lowProfile {
  64. // Create stream manager for outgoing connections
  65. mgr, err = stream.NewConnManager(10, c.MaxStreams)
  66. if err != nil {
  67. return err
  68. }
  69. // Attach it to the same context
  70. go func() {
  71. <-ctx.Done()
  72. mgr.Close()
  73. }()
  74. }
  75. // Set stream handler during runtime
  76. n.Host().SetStreamHandler(protocol.EdgeVPN.ID(), streamHandler(b, ifce, c, nc))
  77. // Announce our IP
  78. ip, _, err := net.ParseCIDR(c.InterfaceAddress)
  79. if err != nil {
  80. return err
  81. }
  82. b.Announce(
  83. ctx,
  84. c.LedgerAnnounceTime,
  85. func() {
  86. machine := &types.Machine{}
  87. // Retrieve current ID for ip in the blockchain
  88. existingValue, found := b.GetKey(protocol.MachinesLedgerKey, ip.String())
  89. existingValue.Unmarshal(machine)
  90. // If mismatch, update the blockchain
  91. if !found || machine.PeerID != n.Host().ID().String() {
  92. updatedMap := map[string]interface{}{}
  93. updatedMap[ip.String()] = newBlockChainData(n, ip.String())
  94. b.Add(protocol.MachinesLedgerKey, updatedMap)
  95. }
  96. },
  97. )
  98. if c.NetLinkBootstrap {
  99. if err := prepareInterface(c); err != nil {
  100. return err
  101. }
  102. }
  103. // read packets from the interface
  104. return readPackets(ctx, mgr, c, n, b, ifce, nc)
  105. }
  106. }
  107. // Start the node and the vpn. Returns an error in case of failure
  108. // When starting the vpn, there is no need to start the node
  109. func Register(p ...Option) ([]node.Option, error) {
  110. return []node.Option{node.WithNetworkService(VPNNetworkService(p...))}, nil
  111. }
  112. func streamHandler(l *blockchain.Ledger, ifce *water.Interface, c *Config, nc node.Config) func(stream network.Stream) {
  113. return func(stream network.Stream) {
  114. if len(nc.PeerTable) == 0 && !l.Exists(protocol.MachinesLedgerKey,
  115. func(d blockchain.Data) bool {
  116. machine := &types.Machine{}
  117. d.Unmarshal(machine)
  118. return machine.PeerID == stream.Conn().RemotePeer().String()
  119. }) {
  120. stream.Reset()
  121. return
  122. }
  123. if len(nc.PeerTable) > 0 {
  124. found := false
  125. for _, p := range nc.PeerTable {
  126. if p.String() == stream.Conn().RemotePeer().String() {
  127. found = true
  128. }
  129. }
  130. if !found {
  131. stream.Reset()
  132. return
  133. }
  134. }
  135. _, err := io.Copy(ifce.ReadWriteCloser, stream)
  136. if err != nil {
  137. stream.Reset()
  138. }
  139. stream.Close()
  140. }
  141. }
  142. func newBlockChainData(n *node.Node, address string) types.Machine {
  143. hostname, _ := os.Hostname()
  144. return types.Machine{
  145. PeerID: n.Host().ID().String(),
  146. Hostname: hostname,
  147. OS: runtime.GOOS,
  148. Arch: runtime.GOARCH,
  149. Version: internal.Version,
  150. Address: address,
  151. }
  152. }
  153. func getFrame(ifce *water.Interface, c *Config) (ethernet.Frame, error) {
  154. var frame ethernet.Frame
  155. frame.Resize(c.MTU)
  156. n, err := ifce.Read([]byte(frame))
  157. if err != nil {
  158. return frame, errors.Wrap(err, "could not read from interface")
  159. }
  160. frame = frame[:n]
  161. return frame, nil
  162. }
  163. func handleFrame(mgr streamManager, frame ethernet.Frame, c *Config, n *node.Node, ip net.IP, ledger *blockchain.Ledger, ifce *water.Interface, nc node.Config) error {
  164. ctx, cancel := context.WithTimeout(context.Background(), c.Timeout)
  165. defer cancel()
  166. var dstIP, srcIP net.IP
  167. var packet layers.IPv4
  168. if err := packet.DecodeFromBytes(frame, gopacket.NilDecodeFeedback); err != nil {
  169. var packet layers.IPv6
  170. if err := packet.DecodeFromBytes(frame, gopacket.NilDecodeFeedback); err != nil {
  171. return errors.Wrap(err, "could not parse header from frame")
  172. } else {
  173. dstIP = packet.DstIP
  174. srcIP = packet.SrcIP
  175. }
  176. } else {
  177. dstIP = packet.DstIP
  178. srcIP = packet.SrcIP
  179. }
  180. dst := dstIP.String()
  181. if c.RouterAddress != "" && srcIP.Equal(ip) {
  182. if _, found := ledger.GetKey(protocol.MachinesLedgerKey, dst); !found {
  183. dst = c.RouterAddress
  184. }
  185. }
  186. var d peer.ID
  187. var err error
  188. notFoundErr := fmt.Errorf("'%s' not found in the routing table", dst)
  189. if len(nc.PeerTable) > 0 {
  190. found := false
  191. for ip, p := range nc.PeerTable {
  192. if ip == dst {
  193. found = true
  194. d = peer.ID(p)
  195. }
  196. }
  197. if !found {
  198. return notFoundErr
  199. }
  200. } else {
  201. // Query the routing table
  202. value, found := ledger.GetKey(protocol.MachinesLedgerKey, dst)
  203. if !found {
  204. return notFoundErr
  205. }
  206. machine := &types.Machine{}
  207. value.Unmarshal(machine)
  208. // Decode the Peer
  209. d, err = peer.Decode(machine.PeerID)
  210. }
  211. if err != nil {
  212. return errors.Wrap(err, "could not decode peer")
  213. }
  214. var stream network.Stream
  215. if mgr != nil {
  216. // Open a stream if necessary
  217. stream, err = mgr.HasStream(n.Host().Network(), d)
  218. if err == nil {
  219. _, err = stream.Write(frame)
  220. if err == nil {
  221. return nil
  222. }
  223. mgr.Disconnected(n.Host().Network(), stream)
  224. }
  225. }
  226. stream, err = n.Host().NewStream(ctx, d, protocol.EdgeVPN.ID())
  227. if err != nil {
  228. return fmt.Errorf("could not open stream to %s: %w", d.String(), err)
  229. }
  230. defer stream.Close()
  231. if mgr != nil {
  232. mgr.Connected(n.Host().Network(), stream)
  233. }
  234. _, err = stream.Write(frame)
  235. return err
  236. }
  237. func connectionWorker(
  238. p chan ethernet.Frame,
  239. mgr streamManager,
  240. c *Config,
  241. n *node.Node,
  242. ip net.IP,
  243. wg *sync.WaitGroup,
  244. ledger *blockchain.Ledger,
  245. ifce *water.Interface,
  246. nc node.Config) {
  247. defer wg.Done()
  248. for f := range p {
  249. if err := handleFrame(mgr, f, c, n, ip, ledger, ifce, nc); err != nil {
  250. c.Logger.Debugf("could not handle frame: %s", err.Error())
  251. }
  252. }
  253. }
  254. // readPackets packets from the interface to the node using the routing table in the blockchain
  255. func readPackets(ctx context.Context, mgr streamManager, c *Config, n *node.Node, ledger *blockchain.Ledger, ifce *water.Interface, nc node.Config) error {
  256. ip, _, err := net.ParseCIDR(c.InterfaceAddress)
  257. if err != nil {
  258. return err
  259. }
  260. wg := new(sync.WaitGroup)
  261. packets := make(chan ethernet.Frame, c.ChannelBufferSize)
  262. defer func() {
  263. close(packets)
  264. wg.Wait()
  265. }()
  266. for i := 0; i < c.Concurrency; i++ {
  267. wg.Add(1)
  268. go connectionWorker(packets, mgr, c, n, ip, wg, ledger, ifce, nc)
  269. }
  270. for {
  271. select {
  272. case <-ctx.Done():
  273. return nil
  274. default:
  275. frame, err := getFrame(ifce, c)
  276. if err != nil {
  277. c.Logger.Errorf("could not get frame '%s'", err.Error())
  278. continue
  279. }
  280. packets <- frame
  281. }
  282. }
  283. }