]> Cypherpunks.ru repositories - govpn.git/blob - src/cypherpunks.ru/govpn/cmd/govpn-server/udp.go
Skip possible invalid memory address during the race
[govpn.git] / src / cypherpunks.ru / govpn / cmd / govpn-server / udp.go
1 /*
2 GoVPN -- simple secure free software virtual private network daemon
3 Copyright (C) 2014-2017 Sergey Matveev <stargrave@stargrave.org>
4
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation, either version 3 of the License, or
8 (at your option) any later version.
9
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
13 GNU General Public License for more details.
14
15 You should have received a copy of the GNU General Public License
16 along with this program.  If not, see <http://www.gnu.org/licenses/>.
17 */
18
19 package main
20
21 import (
22         "log"
23         "net"
24
25         "cypherpunks.ru/govpn"
26 )
27
28 type UDPSender struct {
29         conn *net.UDPConn
30         addr *net.UDPAddr
31 }
32
33 func (c UDPSender) Write(data []byte) (int, error) {
34         return c.conn.WriteToUDP(data, c.addr)
35 }
36
37 var (
38         // Buffers for UDP parallel processing
39         udpBufs = make(chan []byte, 1<<8)
40 )
41
42 func startUDP() {
43         bind, err := net.ResolveUDPAddr("udp", *bindAddr)
44         if err != nil {
45                 log.Fatalln("Can not resolve bind address:", err)
46         }
47         conn, err := net.ListenUDP("udp", bind)
48         if err != nil {
49                 log.Fatalln("Can not listen on UDP:", err)
50         }
51         govpn.BothPrintf(`[udp-listen bind="%s"]`, *bindAddr)
52
53         udpBufs <- make([]byte, govpn.MTUMax)
54         go func() {
55                 var buf []byte
56                 var raddr *net.UDPAddr
57                 var addr string
58                 var n int
59                 var err error
60                 var ps *PeerState
61                 var hs *govpn.Handshake
62                 var addrPrev string
63                 var exists bool
64                 var peerID *govpn.PeerID
65                 var conf *govpn.PeerConf
66                 for {
67                         buf = <-udpBufs
68                         n, raddr, err = conn.ReadFromUDP(buf)
69                         if err != nil {
70                                 govpn.Printf(`[receive-failed bind="%s" err="%s"]`, *bindAddr, err)
71                                 break
72                         }
73                         addr = raddr.String()
74
75                         peersLock.RLock()
76                         ps, exists = peers[addr]
77                         peersLock.RUnlock()
78                         if exists {
79                                 go func(peer *govpn.Peer, tap *govpn.TAP, buf []byte, n int) {
80                                         peer.PktProcess(buf[:n], tap, true)
81                                         udpBufs <- buf
82                                 }(ps.peer, ps.tap, buf, n)
83                                 continue
84                         }
85
86                         hsLock.RLock()
87                         hs, exists = handshakes[addr]
88                         hsLock.RUnlock()
89                         if !exists {
90                                 peerID = idsCache.Find(buf[:n])
91                                 if peerID == nil {
92                                         govpn.Printf(`[identity-unknown bind="%s" addr="%s"]`, *bindAddr, addr)
93                                         udpBufs <- buf
94                                         continue
95                                 }
96                                 conf = confs[*peerID]
97                                 if conf == nil {
98                                         govpn.Printf(
99                                                 `[conf-get-failed bind="%s" peer="%s"]`,
100                                                 *bindAddr, peerID.String(),
101                                         )
102                                         udpBufs <- buf
103                                         continue
104                                 }
105                                 hs := govpn.NewHandshake(
106                                         addr,
107                                         UDPSender{conn: conn, addr: raddr},
108                                         conf,
109                                 )
110                                 hs.Server(buf[:n])
111                                 udpBufs <- buf
112                                 hsLock.Lock()
113                                 handshakes[addr] = hs
114                                 hsLock.Unlock()
115                                 continue
116                         }
117
118                         peer := hs.Server(buf[:n])
119                         if peer == nil {
120                                 udpBufs <- buf
121                                 continue
122                         }
123                         govpn.Printf(
124                                 `[handshake-completed bind="%s" addr="%s" peer="%s"]`,
125                                 *bindAddr, addr, peerID.String(),
126                         )
127                         hs.Zero()
128                         hsLock.Lock()
129                         delete(handshakes, addr)
130                         hsLock.Unlock()
131
132                         go func() {
133                                 udpBufs <- make([]byte, govpn.MTUMax)
134                                 udpBufs <- make([]byte, govpn.MTUMax)
135                         }()
136                         peersByIDLock.RLock()
137                         addrPrev, exists = peersByID[*peer.ID]
138                         peersByIDLock.RUnlock()
139                         var peerPrev *PeerState
140                         if exists {
141                                 peersLock.Lock()
142                                 peerPrev = peers[addrPrev]
143                                 if peerPrev == nil {
144                                         exists = false
145                                         peersLock.Unlock()
146                                 }
147                         }
148                         if exists {
149                                 peerPrev.terminator <- struct{}{}
150                                 psNew := &PeerState{
151                                         peer:       peer,
152                                         tap:        peerPrev.tap,
153                                         terminator: make(chan struct{}),
154                                 }
155                                 go func(peer *govpn.Peer, tap *govpn.TAP, terminator chan struct{}) {
156                                         govpn.PeerTapProcessor(peer, tap, terminator)
157                                         <-udpBufs
158                                         <-udpBufs
159                                 }(psNew.peer, psNew.tap, psNew.terminator)
160                                 peersByIDLock.Lock()
161                                 kpLock.Lock()
162                                 delete(peers, addrPrev)
163                                 delete(knownPeers, addrPrev)
164                                 peers[addr] = psNew
165                                 knownPeers[addr] = &peer
166                                 peersByID[*peer.ID] = addr
167                                 peersLock.Unlock()
168                                 peersByIDLock.Unlock()
169                                 kpLock.Unlock()
170                                 govpn.Printf(
171                                         `[rehandshake-completed bind="%s" peer="%s"]`,
172                                         *bindAddr, peer.ID.String(),
173                                 )
174                         } else {
175                                 go func(addr string, peer *govpn.Peer) {
176                                         ifaceName, err := callUp(peer.ID, peer.Addr)
177                                         if err != nil {
178                                                 return
179                                         }
180                                         tap, err := govpn.TAPListen(ifaceName, peer.MTU)
181                                         if err != nil {
182                                                 govpn.Printf(
183                                                         `[tap-failed bind="%s" peer="%s" err="%s"]`,
184                                                         *bindAddr, peer.ID.String(), err,
185                                                 )
186                                                 return
187                                         }
188                                         psNew := &PeerState{
189                                                 peer:       peer,
190                                                 tap:        tap,
191                                                 terminator: make(chan struct{}),
192                                         }
193                                         go func(peer *govpn.Peer, tap *govpn.TAP, terminator chan struct{}) {
194                                                 govpn.PeerTapProcessor(peer, tap, terminator)
195                                                 <-udpBufs
196                                                 <-udpBufs
197                                         }(psNew.peer, psNew.tap, psNew.terminator)
198                                         peersLock.Lock()
199                                         peersByIDLock.Lock()
200                                         kpLock.Lock()
201                                         peers[addr] = psNew
202                                         knownPeers[addr] = &peer
203                                         peersByID[*peer.ID] = addr
204                                         peersLock.Unlock()
205                                         peersByIDLock.Unlock()
206                                         kpLock.Unlock()
207                                         govpn.Printf(
208                                                 `[peer-created bind="%s" peer="%s"]`,
209                                                 *bindAddr,
210                                                 peer.ID.String(),
211                                         )
212                                 }(addr, peer)
213                         }
214                         udpBufs <- buf
215                 }
216         }()
217 }