Commit Graph
174 Commits
Author SHA1 Message Date
David Fifield ebb82e62e9 Simplify with gofmt -s. 2020-08-21 14:11:58 -06:00
David Fifield e1e27bd4ce Comment typo. 2020-07-26 09:59:27 -06:00
David Fifield cd40a072ba Add another test case for a truncated DNS name compression pointer. 2020-05-15 11:02:13 -06:00
David Fifield b209ba29ed Add a fuzzing harness for the dns module. 2020-05-06 14:39:55 -06:00
David Fifield 8616ac4f91 Fix dns.TestEncodeRDataTXT.
It was always failing because of a debugging line I had left in.
2020-05-06 14:39:55 -06:00
David Fifield e8647f61e0 Add SSH SOCKS and Tor bridge instructions. v0.20200506.0 2020-05-06 12:20:53 -06:00
David Fifield a0a4d6c6b4 TODO with srcport randomization idea. 2020-05-05 18:47:09 -06:00
David Fifield 9cdd7aada1 Add CHANGELOG. 2020-05-05 18:21:46 -06:00
David Fifield ee6b58aca2 Caveat about TLS fingerprint. 2020-05-04 19:53:34 -06:00
David Fifield ad68ec9aba Typo fix. 2020-05-03 22:13:37 -06:00
David Fifield 98476fa843 Put web page in README. v0.20200504.0 2020-05-03 22:08:43 -06:00
David Fifield 769cbd726f Documentation updates. 2020-05-03 22:02:38 -06:00
David Fifield 3254c1c81e Open the client's local listener first. v0.20200430.0 2020-04-29 23:56:36 -06:00
David Fifield e48d53ceb0 Fix a log message. 2020-04-29 23:44:25 -06:00
David Fifield 15c272edc4 Note to self about multiple sendLoop. 2020-04-29 23:29:39 -06:00
David Fifield 8f965fe37b Fix sending of leftover packets.
There was a logic error in the code. The nextP variable was used to
store the packet that was too big to pack into the most recent DNS
response. But nextP was not tied to any particular ClientID; instead it
would be sent to whatever client happened to be the recipient of the
next response.

The confusion didn't cause connections to fail completely; any
misdirected packets were treated as out-of-sequence garbage by KCP and
dropped. But it hurt performance a lot: I saw a download go from 300
KB/s to 50 KB/s just by connecting a second client with a different
ClientID (not even sending or receiving with the second client). The
reason is that a fraction of the packets intended for the downloading
client were instead sent to the idle client, which to the downloading
client looks like a packet drop, requiring a retransmission by the
server.

We fix it by placing the leftover packet in a per-ClientID stash, rather
than a variable shared by all ClientIDs.
2020-04-29 23:29:39 -06:00
David Fifield 938463ce07 Add a one-packet "stash" to QueuePacketConn.
I want a way to "unread" a packet from an send queue, in the case where
I'm packing packets into a fixed space and don't know when I'm done
until I've read one too many packets. There's no way to insert the extra
packet at the head of the cannel representing the send queue, so that it
will be the next thing received from OutgoingQueue. Instead, add an
separate one-element queue called the stash. The caller can stash an
excess packet, then prioritize checking it in the next round by calling
Unstash before OutgoingQueue.
2020-04-29 23:06:27 -06:00
David Fifield 8526369e65 Give next-response/timer-expired priority over packing downstream.
I don't know what I was thinking in
f1ee951fd6. The way it was written, if
there were not immediately additional packets to pack into the
downstream, it would stop trying to pack and would instead wait until
the maxResponseDelay or another response to send. What I meant is that
the timer and the next-response channel should have priority, if either
of those is true *and* there is additional downstream available to pack.
Only when both of those are false should we try to pack downstream data.
2020-04-29 20:56:33 -06:00
David Fifield 2371fb4558 Attempt to extract packets only if we got a ClientID. 2020-04-29 12:57:06 -06:00
David Fifield 24d7fd82b2 Log "too short for ClientID" on when it's a non-error response.
The server would log "NXDOMAIN: 0 bytes are too short to contain a
ClientID" even in the common cases where it got an A or NS query from
the resolver (possibly from QNAME minimization).
2020-04-29 12:56:41 -06:00
David Fifield f6ca82d08c Buffer reads and writes in TLSPacketConn. 2020-04-29 12:44:07 -06:00
David Fifield ed2678917e Add a missing error check in TLSPacketConn.sendLoop. 2020-04-29 12:42:39 -06:00
David Fifield 4663433c08 Do receive-triggered polls based packets received.
Not amount of raw payload. This allows for the case where the received
payload is only padding, for example. (That can't happen with the
current downstream encoding scheme, which doesn't allow for padding, so
I believe this change results in equivalent behavior.)
v0.20200429.0
2020-04-29 09:45:29 -06:00
David Fifield 05444dcb22 smux Stream.Write may also return EOF. v0.20200426.0 2020-04-25 21:27:14 -06:00
David Fifield 241225df1d Add -mtu option to server. 2020-04-25 20:54:09 -06:00
David Fifield f7e028a697 Log when truncating a response.
We don't expect this to happen often. It probably indicates an error.
2020-04-25 20:28:37 -06:00
David Fifield e328c57b21 Log pubkey before MTU. 2020-04-25 20:28:37 -06:00
David Fifield a00ef8f9ea Compute maxEncodedPayload automatically from maxUDPPayload.
Previously I had maxEncodedPayload hard-coded as a separate constant,
but it is completely dependent on maxUDPPayload. We compute it by
actually constructing wire-format packets and taking their length, which
should be less fragile than the formula I previously had commented,
though it requires some synchronization between the sendLoop and
computeMaxEncodedPayload functions.
2020-04-25 20:28:37 -06:00
David Fifield e5efc55f23 Extract the ClientID outside of responseFor. 2020-04-25 19:51:15 -06:00
David Fifield e5b6d48b41 Fix some comment typos. 2020-04-25 19:50:26 -06:00
David Fifield 9ee6bf8abf Use wg.Add(2) instead of 2 × wg.Add(1). 2020-04-23 15:51:53 -06:00
David Fifield 7fa2bcf441 TODO file with idea about UDP payload size. 2020-04-20 20:07:15 -06:00
David Fifield dbce5322a6 README updates and fixes. 2020-04-19 21:50:40 -06:00
David Fifield 63f3ded841 README typo fix. 2020-04-19 19:23:21 -06:00
David Fifield 32d319a75b iptables command typo fix. 2020-04-19 19:15:50 -06:00
David Fifield 9f430df8aa Make the privkey file only readable by the user. v0.20200419.0 2020-04-19 17:31:16 -06:00
David Fifield a650238f1e Don't log QTYPE != TXT errors. 2020-04-19 17:16:27 -06:00
David Fifield d14deab12b Documentation and light refactoring. 2020-04-19 17:16:27 -06:00
David Fifield 83a67e3874 Fix a bug in noise.readMessage.
Was returning nil in case of an error from io.ReadFull, and even then it
should have been io.ErrUnexpectedEOF, not io.EOF.
2020-04-19 16:52:48 -06:00
David Fifield a6af2f1df1 Make -udp required, resolve in main. 2020-04-19 16:20:50 -06:00
David Fifield 813a8564e8 Move some helper functions into dns.go. 2020-04-19 11:29:50 -06:00
David Fifield d42f7ea187 Add test for dns.EncodeRDataTXT. 2020-04-19 11:05:36 -06:00
David Fifield c33077e885 Refactor MessageFromWireFormat and writeMessage.
Make MessageFromWireFormat responsible for checking the EOF condition.
2020-04-19 10:57:55 -06:00
David Fifield f168777a13 dns Message.Opcode method. 2020-04-19 10:33:40 -06:00
David Fifield 4b0b144257 Consolidate the authoritative domain check.
Formerly this was split into two pieces: one that did the domain check
and set the AA bit, and another that checked the AA bit and returned an
error if it was not set. It was done in two parts because the check for
UDP payload size occurred in the middle. Since 59f03791 the payload
check is moved to the end, so we can do the authoritative domain check
in one piece.
2020-04-19 10:28:56 -06:00
David Fifield 53a6eeed5d Note on covertness after the tunnel server. 2020-04-19 10:27:08 -06:00
David Fifield 3bd72bf336 Notes on -privkey/-privkey-file/-pubkey/-pubkey-file. 2020-04-19 10:10:15 -06:00
David Fifield 0567fa9abb Remove addr fro "cannot parse DNS query" log message. 2020-04-19 09:44:05 -06:00
David Fifield e9a98c3aef Avoid logging EOF and ErrClosedPipe errors.
smux Stream.WriteTo may return io.EOF, which breaks the contract of
io.Copy that says it should not return io.EOF. smux.Stream doesn't have
a unidirectional shutdown, so we always end up slamming it shut in both
directions and leave the other direction with a broken pipe.
2020-04-19 02:13:48 -06:00
David Fifield 34b7e82af4 More logging of query validation errors in server. 2020-04-19 01:17:33 -06:00