Commit Graph
84 Commits
Author SHA1 Message Date
David Fifield 813a8564e8 Move some helper functions into dns.go. 2020-04-19 11:29:50 -06:00
David Fifield d42f7ea187 Add test for dns.EncodeRDataTXT. 2020-04-19 11:05:36 -06:00
David Fifield c33077e885 Refactor MessageFromWireFormat and writeMessage.
Make MessageFromWireFormat responsible for checking the EOF condition.
2020-04-19 10:57:55 -06:00
David Fifield f168777a13 dns Message.Opcode method. 2020-04-19 10:33:40 -06:00
David Fifield 4b0b144257 Consolidate the authoritative domain check.
Formerly this was split into two pieces: one that did the domain check
and set the AA bit, and another that checked the AA bit and returned an
error if it was not set. It was done in two parts because the check for
UDP payload size occurred in the middle. Since 59f03791 the payload
check is moved to the end, so we can do the authoritative domain check
in one piece.
2020-04-19 10:28:56 -06:00
David Fifield 53a6eeed5d Note on covertness after the tunnel server. 2020-04-19 10:27:08 -06:00
David Fifield 3bd72bf336 Notes on -privkey/-privkey-file/-pubkey/-pubkey-file. 2020-04-19 10:10:15 -06:00
David Fifield 0567fa9abb Remove addr fro "cannot parse DNS query" log message. 2020-04-19 09:44:05 -06:00
David Fifield e9a98c3aef Avoid logging EOF and ErrClosedPipe errors.
smux Stream.WriteTo may return io.EOF, which breaks the contract of
io.Copy that says it should not return io.EOF. smux.Stream doesn't have
a unidirectional shutdown, so we always end up slamming it shut in both
directions and leave the other direction with a broken pipe.
2020-04-19 02:13:48 -06:00
David Fifield 34b7e82af4 More logging of query validation errors in server. 2020-04-19 01:17:33 -06:00
David Fifield 98bf401738 Use NXDOMAIN rather than FORMERR for QTYPE != TXT. 2020-04-19 01:13:35 -06:00
David Fifield 59f03791df Do the payload size check after the TXT and base32 checks.
That way we can respond with NXDOMAIN rather than FORMERR to more of the
random queries that arrive.
2020-04-19 00:59:04 -06:00
David Fifield 04e1295e52 Infer a payload size of 512 even when there is no OPT RR.
Before we were inferring a size of 0. It would still be rejected for
being too small, but was confusing with the log messages I am adding.
2020-04-19 00:53:34 -06:00
David Fifield 294f1acc7d Fix second AA check. 2020-04-19 00:53:34 -06:00
David Fifield 1e57ed8d42 Add missing return for EDNS version != 0. 2020-04-19 00:53:34 -06:00
David Fifield 7fad23ceca Reduce maxUDPPayload to 1232 for compatibility with Quad9. 2020-04-19 00:53:34 -06:00
David Fifield 079a24146c README. 2020-04-19 00:21:31 -06:00
David Fifield e7098959e2 Move global base32Encoding into dns.go. 2020-04-18 23:39:35 -06:00
David Fifield b7c18be90f Lowercase base32-encoded data in DNS names. 2020-04-18 23:39:35 -06:00
David Fifield 41c146355a Do MTU check first. 2020-04-18 19:05:23 -06:00
David Fifield 0a630f91c5 Log stream begin/end in server, log conv in client. 2020-04-18 19:05:23 -06:00
David Fifield 7ed79218eb Insert more padding when polling. 2020-04-18 18:46:54 -06:00
David Fifield b1bf9164a7 -privkey-file and -pubkey-file options. 2020-04-18 17:56:45 -06:00
David Fifield 505db3ec23 Server -privkey option and client -pubkey option. 2020-04-18 17:35:32 -06:00
David Fifield 7dc344713c Add a noise.PubkeyFromPrivkey function. 2020-04-18 16:02:14 -06:00
David Fifield cd03021417 Note -udp is required on server. 2020-04-18 16:02:14 -06:00
David Fifield 117f73aae9 Rename ClientMap to RemoteMap.
We're now using it (via QueuePacketConn) in DNSPacketConn,
HTTPPacketConn, and TLSPacketConn, where there remote peer is actually a
server, not a client.
2020-04-18 16:02:14 -06:00
David Fifield b98eb2c75e Move dummyAddr to turbotunnel.DummyAddr. 2020-04-18 16:02:14 -06:00
David Fifield 82ee14fefa Emit a log line even if we take no action on an unknown status code. 2020-04-18 16:02:14 -06:00
David Fifield b0f99e72bb Handle other unknown response status codes the same as 429. 2020-04-18 16:02:14 -06:00
David Fifield e501935578 Handle 429 Too Many Requests. 2020-04-18 16:02:14 -06:00
David Fifield 973f6310c5 Don't expire ClientMap if timeout is zero. 2020-04-18 16:02:14 -06:00
David Fifield 317c2c43d0 Don't send User-Agent.
HTTP header now looks like
```
POST / HTTP/1.1
Host: 127.0.0.1:8000
Content-Length: 221
Accept: application/dns-message
Content-Type: application/dns-message
Accept-Encoding: gzip
```
2020-04-18 16:02:14 -06:00
David Fifield 087d3b25dd Refactor HTTP response handling. 2020-04-18 16:02:14 -06:00
David Fifield e772e7bf2f Add a timeout to HTTP requests and follow redirects. 2020-04-18 16:02:14 -06:00
David Fifield f69e4e0d71 Truncation and TC bit in responses. 2020-04-18 16:02:14 -06:00
David Fifield e53d332eca Reduce response delay to 1 s.
To be below the reported Quad9 timeout.
2020-04-18 16:02:14 -06:00
David Fifield 9c827e579c On third thought, do close send queues when expiring.
Callers don't have access to the queue except through WriteTo, so they
can't cause a panic by writing to a closed channel.
2020-04-18 16:02:14 -06:00
David Fifield 5350ea1e68 Increase initPollDelay to 500 ms. 2020-04-18 16:02:14 -06:00
David Fifield 7cbddf5fd9 Rework polling.
Give priority to data-carrying packets over polling packets.
Discard a polling packet whenever sending a data-carrying packet.
2020-04-18 16:02:14 -06:00
David Fifield 06144f76ae -dot mode. 2020-04-18 16:02:11 -06:00
David Fifield 1907daeba0 Simplify HTTPPacketConn. 2020-04-18 14:34:10 -06:00
David Fifield be9c3f1ac7 Refactor PacketConn handling. 2020-04-18 14:34:10 -06:00
David Fifield 0f65c5077c Use a global CipherSuite. 2020-04-18 14:34:10 -06:00
David Fifield 7f3e9e4571 Overlay a noise layer atop KCP. 2020-04-18 14:34:10 -06:00
David Fifield f2423f959a noise socket abstraction 2020-04-18 14:34:10 -06:00
David Fifield 3f98c62207 Log when there's an error opening a stream. 2020-04-18 14:34:10 -06:00
David Fifield f8b9d73493 Switch up order of query checks in server.
We should set the AA bit if it applies, even if there are things wrong
with the query. An EDNS(0)-related error supersedes all others.
2020-04-18 14:34:10 -06:00
David Fifield 0a568a386b Need to set RR class in responses.
The lack of this (Class==0) worked fine with Google UDP and DoH, and
Cloudflare UDP, but failed with Cloudflare DoH (the DoH resolver
stripped the TXT RR).
2020-04-18 14:34:04 -06:00
David Fifield a6c891c5ae -doh mode. 2020-04-18 14:33:39 -06:00