)
const (
- MessageInitiationSize = 148
- MessageResponseSize = 92
- MessageCookieReplySize = 64
- MessageTransportSize = 16 + poly1305.TagSize // size of empty transport
+ MessageInitiationSize = 148
+ MessageResponseSize = 92
+ MessageCookieReplySize = 64
+ MessageTransportHeaderSize = 16
+ MessageTransportSize = MessageTransportHeaderSize + poly1305.TagSize // size of empty transport
)
const (
keyPair.sendNonce = 0
keyPair.recvNonce = 0
keyPair.created = time.Now()
+ keyPair.localIndex = peer.handshake.localIndex
+ keyPair.remoteIndex = peer.handshake.remoteIndex
// remap index
if kp.previous != nil {
kp.previous.send = nil
kp.previous.recv = nil
- peer.device.indices.Delete(kp.previous.id)
+ peer.device.indices.Delete(kp.previous.localIndex)
}
kp.previous = kp.current
kp.current = keyPair
// handle packet
packet = packet[:size]
+ debugLog.Println("GOT:", packet)
msgType := binary.LittleEndian.Uint32(packet[:4])
func() {
// check for replay
+ // strip padding
+
// check for keep-alive
if len(elem.packet) == 0 {
case packet = <-device.queue.inbound:
}
- device.log.Debug.Println("GOT:", packet)
-
size, err := tun.Write(packet)
device.log.Debug.Println("DEBUG:", size, err)
if err != nil {
}
}
- logger.Println("PACKET:", packet)
-
// wait for key pair
for {
work.peer = peer
work.mutex.Lock()
- logger.Println("WORK:", work)
-
packet = nil
// drop packets until there is space
// pad packet
- padding := device.mtu - len(work.packet)
+ padding := device.mtu - len(work.packet) - MessageTransportSize
if padding < 0 {
work.Drop()
continue
for n := 0; n < padding; n += 1 {
work.packet = append(work.packet, 0)
}
- device.log.Debug.Println(work.packet)
+ content := work.packet[MessageTransportHeaderSize:]
+ copy(content, work.packet)
+
+ // prepare header
- // encrypt
+ binary.LittleEndian.PutUint32(work.packet[:4], MessageTransportType)
+ binary.LittleEndian.PutUint32(work.packet[4:8], work.keyPair.remoteIndex)
+ binary.LittleEndian.PutUint64(work.packet[8:16], work.nonce)
+
+ device.log.Debug.Println(work.packet, work.nonce)
+
+ // encrypt content
binary.LittleEndian.PutUint64(nonce[4:], work.nonce)
- work.packet = work.keyPair.send.Seal(
- work.packet[:0],
+ work.keyPair.send.Seal(
+ content[:0],
nonce[:],
- work.packet,
+ content,
nil,
)
work.mutex.Unlock()
+ device.log.Debug.Println(work.packet, work.nonce)
+
// initiate new handshake
work.peer.KeepKeyFreshSending()