yuhan6665
2026-09-20 21:57:26 +00:00
committed by RPRX
parent 8cdf7bf9c7
commit 9124ee149d
25 changed files with 1491 additions and 1118 deletions
+34 -28
View File
@@ -27,13 +27,13 @@ package reality
// https://www.imperialviolet.org/2013/02/04/luckythirteen.html.
import (
"bytes"
"context"
"crypto"
"crypto/aes"
"crypto/cipher"
"crypto/ecdsa"
"crypto/ed25519"
"crypto/mldsa"
"crypto/mlkem"
"crypto/rsa"
"crypto/sha256"
@@ -56,6 +56,7 @@ import (
"golang.org/x/crypto/hkdf"
)
//////////////////////////////////// [REALITY] SECTION: Reality server
type CloseWriteConn interface {
net.Conn
CloseWrite() error
@@ -493,6 +494,7 @@ func Server(ctx context.Context, conn net.Conn, config *Config) (*Conn, error) {
return c
*/
}
//////////////////////////////////// [REALITY] SECTION END
// Client returns a new TLS client side connection
// using conn as the underlying transport.
@@ -512,6 +514,7 @@ func Client(conn net.Conn, config *Config) *Conn {
type listener struct {
net.Listener
config *Config
//////////////////////////////////// [REALITY] SECTION: listener
conns chan net.Conn
err error
}
@@ -563,6 +566,7 @@ func NewListener(inner net.Listener, config *Config) net.Listener {
}
return l
}
//////////////////////////////////// [REALITY] SECTION END
// Listen creates a TLS listener accepting connections on the
// given network address using net.Listen.
@@ -583,6 +587,8 @@ func Listen(network, laddr string, config *Config) (net.Listener, error) {
type timeoutError struct{}
var _ error = timeoutError{}
func (timeoutError) Error() string { return "tls: DialWithDialer timed out" }
func (timeoutError) Timeout() bool { return true }
func (timeoutError) Temporary() bool { return true }
@@ -710,10 +716,6 @@ func (d *Dialer) DialContext(ctx context.Context, network, addr string) (net.Con
// files. The files must contain PEM encoded data. The certificate file may
// contain intermediate certificates following the leaf certificate to form a
// certificate chain. On successful return, Certificate.Leaf will be populated.
//
// Before Go 1.23 Certificate.Leaf was left nil, and the parsed certificate was
// discarded. This behavior can be re-enabled by setting "x509keypairleaf=0"
// in the GODEBUG environment variable.
func LoadX509KeyPair(certFile, keyFile string) (Certificate, error) {
certPEMBlock, err := os.ReadFile(certFile)
if err != nil {
@@ -728,10 +730,6 @@ func LoadX509KeyPair(certFile, keyFile string) (Certificate, error) {
// X509KeyPair parses a public/private key pair from a pair of
// PEM encoded data. On successful return, Certificate.Leaf will be populated.
//
// Before Go 1.23 Certificate.Leaf was left nil, and the parsed certificate was
// discarded. This behavior can be re-enabled by setting "x509keypairleaf=0"
// in the GODEBUG environment variable.
func X509KeyPair(certPEMBlock, keyPEMBlock []byte) (Certificate, error) {
fail := func(err error) (Certificate, error) { return Certificate{}, err }
@@ -785,7 +783,6 @@ func X509KeyPair(certPEMBlock, keyPEMBlock []byte) (Certificate, error) {
if err != nil {
return fail(err)
}
cert.Leaf = x509Cert
cert.PrivateKey, err = parsePrivateKey(keyDERBlock.Bytes)
@@ -799,7 +796,7 @@ func X509KeyPair(certPEMBlock, keyPEMBlock []byte) (Certificate, error) {
if !ok {
return fail(errors.New("tls: private key type does not match public key type"))
}
if pub.N.Cmp(priv.N) != 0 {
if !priv.PublicKey.Equal(pub) {
return fail(errors.New("tls: private key does not match public key"))
}
case *ecdsa.PublicKey:
@@ -807,7 +804,7 @@ func X509KeyPair(certPEMBlock, keyPEMBlock []byte) (Certificate, error) {
if !ok {
return fail(errors.New("tls: private key type does not match public key type"))
}
if pub.X.Cmp(priv.X) != 0 || pub.Y.Cmp(priv.Y) != 0 {
if !priv.PublicKey.Equal(pub) {
return fail(errors.New("tls: private key does not match public key"))
}
case ed25519.PublicKey:
@@ -815,7 +812,15 @@ func X509KeyPair(certPEMBlock, keyPEMBlock []byte) (Certificate, error) {
if !ok {
return fail(errors.New("tls: private key type does not match public key type"))
}
if !bytes.Equal(priv.Public().(ed25519.PublicKey), pub) {
if !priv.Public().(ed25519.PublicKey).Equal(pub) {
return fail(errors.New("tls: private key does not match public key"))
}
case *mldsa.PublicKey:
priv, ok := cert.PrivateKey.(*mldsa.PrivateKey)
if !ok {
return fail(errors.New("tls: private key type does not match public key type"))
}
if !priv.PublicKey().Equal(pub) {
return fail(errors.New("tls: private key does not match public key"))
}
default:
@@ -829,20 +834,21 @@ func X509KeyPair(certPEMBlock, keyPEMBlock []byte) (Certificate, error) {
// PKCS #1 private keys by default, while OpenSSL 1.0.0 generates PKCS #8 keys.
// OpenSSL ecparam generates SEC1 EC private keys for ECDSA. We try all three.
func parsePrivateKey(der []byte) (crypto.PrivateKey, error) {
if key, err := x509.ParsePKCS1PrivateKey(der); err == nil {
key, err := x509.ParsePKCS8PrivateKey(der)
pkcs8Err := err // Return the PKCS#8 error if all parsing attempts fail.
if err != nil {
key, err = x509.ParsePKCS1PrivateKey(der)
}
if err != nil {
key, err = x509.ParseECPrivateKey(der)
}
if err != nil {
return nil, fmt.Errorf("tls: failed to parse private key: %w", pkcs8Err)
}
switch key := key.(type) {
case *rsa.PrivateKey, *ecdsa.PrivateKey, ed25519.PrivateKey, *mldsa.PrivateKey:
return key, nil
default:
return nil, errors.New("tls: found unknown private key type in PKCS#8 wrapping")
}
if key, err := x509.ParsePKCS8PrivateKey(der); err == nil {
switch key := key.(type) {
case *rsa.PrivateKey, *ecdsa.PrivateKey, ed25519.PrivateKey:
return key, nil
default:
return nil, errors.New("tls: found unknown private key type in PKCS#8 wrapping")
}
}
if key, err := x509.ParseECPrivateKey(der); err == nil {
return key, nil
}
return nil, errors.New("tls: failed to parse private key")
}
}