David Fifield
813a8564e8
Move some helper functions into dns.go.
2020-04-19 11:29:50 -06:00
David Fifield
d42f7ea187
Add test for dns.EncodeRDataTXT.
2020-04-19 11:05:36 -06:00
David Fifield
c33077e885
Refactor MessageFromWireFormat and writeMessage.
...
Make MessageFromWireFormat responsible for checking the EOF condition.
2020-04-19 10:57:55 -06:00
David Fifield
f168777a13
dns Message.Opcode method.
2020-04-19 10:33:40 -06:00
David Fifield
4b0b144257
Consolidate the authoritative domain check.
...
Formerly this was split into two pieces: one that did the domain check
and set the AA bit, and another that checked the AA bit and returned an
error if it was not set. It was done in two parts because the check for
UDP payload size occurred in the middle. Since 59f03791 the payload
check is moved to the end, so we can do the authoritative domain check
in one piece.
2020-04-19 10:28:56 -06:00
David Fifield
53a6eeed5d
Note on covertness after the tunnel server.
2020-04-19 10:27:08 -06:00
David Fifield
3bd72bf336
Notes on -privkey/-privkey-file/-pubkey/-pubkey-file.
2020-04-19 10:10:15 -06:00
David Fifield
0567fa9abb
Remove addr fro "cannot parse DNS query" log message.
2020-04-19 09:44:05 -06:00
David Fifield
e9a98c3aef
Avoid logging EOF and ErrClosedPipe errors.
...
smux Stream.WriteTo may return io.EOF, which breaks the contract of
io.Copy that says it should not return io.EOF. smux.Stream doesn't have
a unidirectional shutdown, so we always end up slamming it shut in both
directions and leave the other direction with a broken pipe.
2020-04-19 02:13:48 -06:00
David Fifield
34b7e82af4
More logging of query validation errors in server.
2020-04-19 01:17:33 -06:00
David Fifield
98bf401738
Use NXDOMAIN rather than FORMERR for QTYPE != TXT.
2020-04-19 01:13:35 -06:00
David Fifield
59f03791df
Do the payload size check after the TXT and base32 checks.
...
That way we can respond with NXDOMAIN rather than FORMERR to more of the
random queries that arrive.
2020-04-19 00:59:04 -06:00
David Fifield
04e1295e52
Infer a payload size of 512 even when there is no OPT RR.
...
Before we were inferring a size of 0. It would still be rejected for
being too small, but was confusing with the log messages I am adding.
2020-04-19 00:53:34 -06:00
David Fifield
294f1acc7d
Fix second AA check.
2020-04-19 00:53:34 -06:00
David Fifield
1e57ed8d42
Add missing return for EDNS version != 0.
2020-04-19 00:53:34 -06:00
David Fifield
7fad23ceca
Reduce maxUDPPayload to 1232 for compatibility with Quad9.
2020-04-19 00:53:34 -06:00
David Fifield
079a24146c
README.
2020-04-19 00:21:31 -06:00
David Fifield
e7098959e2
Move global base32Encoding into dns.go.
2020-04-18 23:39:35 -06:00
David Fifield
b7c18be90f
Lowercase base32-encoded data in DNS names.
2020-04-18 23:39:35 -06:00
David Fifield
41c146355a
Do MTU check first.
2020-04-18 19:05:23 -06:00
David Fifield
0a630f91c5
Log stream begin/end in server, log conv in client.
2020-04-18 19:05:23 -06:00
David Fifield
7ed79218eb
Insert more padding when polling.
2020-04-18 18:46:54 -06:00
David Fifield
b1bf9164a7
-privkey-file and -pubkey-file options.
2020-04-18 17:56:45 -06:00
David Fifield
505db3ec23
Server -privkey option and client -pubkey option.
2020-04-18 17:35:32 -06:00
David Fifield
7dc344713c
Add a noise.PubkeyFromPrivkey function.
2020-04-18 16:02:14 -06:00
David Fifield
cd03021417
Note -udp is required on server.
2020-04-18 16:02:14 -06:00
David Fifield
117f73aae9
Rename ClientMap to RemoteMap.
...
We're now using it (via QueuePacketConn) in DNSPacketConn,
HTTPPacketConn, and TLSPacketConn, where there remote peer is actually a
server, not a client.
2020-04-18 16:02:14 -06:00
David Fifield
b98eb2c75e
Move dummyAddr to turbotunnel.DummyAddr.
2020-04-18 16:02:14 -06:00
David Fifield
82ee14fefa
Emit a log line even if we take no action on an unknown status code.
2020-04-18 16:02:14 -06:00
David Fifield
b0f99e72bb
Handle other unknown response status codes the same as 429.
2020-04-18 16:02:14 -06:00
David Fifield
e501935578
Handle 429 Too Many Requests.
2020-04-18 16:02:14 -06:00
David Fifield
973f6310c5
Don't expire ClientMap if timeout is zero.
2020-04-18 16:02:14 -06:00
David Fifield
317c2c43d0
Don't send User-Agent.
...
HTTP header now looks like
```
POST / HTTP/1.1
Host: 127.0.0.1:8000
Content-Length: 221
Accept: application/dns-message
Content-Type: application/dns-message
Accept-Encoding: gzip
```
2020-04-18 16:02:14 -06:00
David Fifield
087d3b25dd
Refactor HTTP response handling.
2020-04-18 16:02:14 -06:00
David Fifield
e772e7bf2f
Add a timeout to HTTP requests and follow redirects.
2020-04-18 16:02:14 -06:00
David Fifield
f69e4e0d71
Truncation and TC bit in responses.
2020-04-18 16:02:14 -06:00
David Fifield
e53d332eca
Reduce response delay to 1 s.
...
To be below the reported Quad9 timeout.
2020-04-18 16:02:14 -06:00
David Fifield
9c827e579c
On third thought, do close send queues when expiring.
...
Callers don't have access to the queue except through WriteTo, so they
can't cause a panic by writing to a closed channel.
2020-04-18 16:02:14 -06:00
David Fifield
5350ea1e68
Increase initPollDelay to 500 ms.
2020-04-18 16:02:14 -06:00
David Fifield
7cbddf5fd9
Rework polling.
...
Give priority to data-carrying packets over polling packets.
Discard a polling packet whenever sending a data-carrying packet.
2020-04-18 16:02:14 -06:00
David Fifield
06144f76ae
-dot mode.
2020-04-18 16:02:11 -06:00
David Fifield
1907daeba0
Simplify HTTPPacketConn.
2020-04-18 14:34:10 -06:00
David Fifield
be9c3f1ac7
Refactor PacketConn handling.
2020-04-18 14:34:10 -06:00
David Fifield
0f65c5077c
Use a global CipherSuite.
2020-04-18 14:34:10 -06:00
David Fifield
7f3e9e4571
Overlay a noise layer atop KCP.
2020-04-18 14:34:10 -06:00
David Fifield
f2423f959a
noise socket abstraction
2020-04-18 14:34:10 -06:00
David Fifield
3f98c62207
Log when there's an error opening a stream.
2020-04-18 14:34:10 -06:00
David Fifield
f8b9d73493
Switch up order of query checks in server.
...
We should set the AA bit if it applies, even if there are things wrong
with the query. An EDNS(0)-related error supersedes all others.
2020-04-18 14:34:10 -06:00
David Fifield
0a568a386b
Need to set RR class in responses.
...
The lack of this (Class==0) worked fine with Google UDP and DoH, and
Cloudflare UDP, but failed with Cloudflare DoH (the DoH resolver
stripped the TXT RR).
2020-04-18 14:34:04 -06:00
David Fifield
a6c891c5ae
-doh mode.
2020-04-18 14:33:39 -06:00