Files
wireguard-go/tun/tun_linux.go
T

446 lines
8.8 KiB
Go
Raw Normal View History

2019-01-02 01:55:51 +01:00
/* SPDX-License-Identifier: MIT
2018-05-03 15:04:00 +02:00
*
2019-01-02 01:55:51 +01:00
* Copyright (C) 2017-2019 WireGuard LLC. All Rights Reserved.
2018-05-03 15:04:00 +02:00
*/
2018-05-23 02:10:54 +02:00
package tun
2017-06-04 21:48:15 +02:00
/* Implementation of the TUN device interface for linux
*/
2017-06-04 21:48:15 +02:00
import (
2018-05-05 02:48:21 +02:00
"bytes"
2017-06-04 21:48:15 +02:00
"errors"
2017-08-17 00:25:39 +02:00
"fmt"
2017-12-04 21:39:06 +01:00
"golang.org/x/net/ipv6"
"golang.org/x/sys/unix"
"golang.zx2c4.com/wireguard/rwcancel"
2017-08-04 16:15:53 +02:00
"net"
2017-06-04 21:48:15 +02:00
"os"
2018-04-18 16:39:14 +02:00
"strconv"
2018-05-21 03:31:44 +02:00
"sync"
2017-11-29 18:46:31 +01:00
"time"
2017-06-04 21:48:15 +02:00
"unsafe"
)
2017-08-17 00:25:39 +02:00
const (
2018-02-13 16:43:07 +01:00
cloneDevicePath = "/dev/net/tun"
ifReqSize = unix.IFNAMSIZ + 64
2017-08-17 00:25:39 +02:00
)
2017-06-04 21:48:15 +02:00
2019-03-01 00:05:57 +01:00
type NativeTun struct {
2018-10-17 21:26:53 +02:00
tunFile *os.File
fd uintptr
fdCancel *rwcancel.RWCancel
2018-05-21 03:31:44 +02:00
index int32 // if index
name string // name of interface
errors chan error // async error handling
events chan TUNEvent // device related events
nopi bool // the device was pased IFF_NO_PI
netlinkSock int
netlinkCancel *rwcancel.RWCancel
hackListenerClosed sync.Mutex
2018-05-14 03:43:56 +02:00
statusListenersShutdown chan struct{}
2017-08-17 00:25:39 +02:00
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) File() *os.File {
2018-10-17 21:26:53 +02:00
return tun.tunFile
2017-11-14 18:26:28 +01:00
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) routineHackListener() {
2018-05-21 03:31:44 +02:00
defer tun.hackListenerClosed.Unlock()
2017-11-29 21:12:09 +01:00
/* This is needed for the detection to work across network namespaces
2017-11-29 18:46:31 +01:00
* If you are reading this and know a better method, please get in touch.
*/
fd := int(tun.fd)
2017-11-29 18:46:31 +01:00
for {
_, err := unix.Write(fd, nil)
2017-11-29 18:46:31 +01:00
switch err {
case unix.EINVAL:
2018-02-11 18:55:30 +01:00
tun.events <- TUNEventUp
2017-11-29 18:46:31 +01:00
case unix.EIO:
2018-02-11 18:55:30 +01:00
tun.events <- TUNEventDown
2017-11-29 18:46:31 +01:00
default:
2018-05-14 02:14:33 +02:00
return
}
select {
2018-05-20 04:03:11 +02:00
case <-time.After(time.Second):
2018-05-14 03:43:56 +02:00
case <-tun.statusListenersShutdown:
2018-05-14 02:14:33 +02:00
return
2017-11-29 18:46:31 +01:00
}
}
}
2018-05-14 02:14:33 +02:00
func createNetlinkSocket() (int, error) {
sock, err := unix.Socket(unix.AF_NETLINK, unix.SOCK_RAW, unix.NETLINK_ROUTE)
2018-02-13 16:43:07 +01:00
if err != nil {
2018-05-14 02:14:33 +02:00
return -1, err
2017-08-17 00:25:39 +02:00
}
saddr := &unix.SockaddrNetlink{
Family: unix.AF_NETLINK,
2018-05-14 02:14:33 +02:00
Groups: uint32((1 << (unix.RTNLGRP_LINK - 1)) | (1 << (unix.RTNLGRP_IPV4_IFADDR - 1)) | (1 << (unix.RTNLGRP_IPV6_IFADDR - 1))),
}
err = unix.Bind(sock, saddr)
if err != nil {
2018-05-14 02:14:33 +02:00
return -1, err
}
2018-05-14 02:14:33 +02:00
return sock, nil
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) routineNetlinkListener() {
2018-05-20 06:38:39 +02:00
defer func() {
unix.Close(tun.netlinkSock)
2018-05-21 03:31:44 +02:00
tun.hackListenerClosed.Lock()
2018-05-20 06:38:39 +02:00
close(tun.events)
}()
2018-05-14 14:08:03 +02:00
2017-08-17 00:25:39 +02:00
for msg := make([]byte, 1<<16); ; {
2018-05-14 14:08:03 +02:00
var err error
var msgn int
for {
msgn, _, _, _, err = unix.Recvmsg(tun.netlinkSock, msg[:], nil, 0)
2018-05-24 15:29:16 +02:00
if err == nil || !rwcancel.RetryAfterError(err) {
2018-05-14 14:08:03 +02:00
break
}
if !tun.netlinkCancel.ReadyRead() {
tun.errors <- fmt.Errorf("netlink socket closed: %s", err.Error())
return
}
}
2017-08-17 00:25:39 +02:00
if err != nil {
2018-05-14 02:14:33 +02:00
tun.errors <- fmt.Errorf("failed to receive netlink message: %s", err.Error())
2017-08-17 00:25:39 +02:00
return
}
2018-05-14 03:43:56 +02:00
select {
case <-tun.statusListenersShutdown:
return
default:
}
2017-08-17 00:25:39 +02:00
for remain := msg[:msgn]; len(remain) >= unix.SizeofNlMsghdr; {
hdr := *(*unix.NlMsghdr)(unsafe.Pointer(&remain[0]))
if int(hdr.Len) > len(remain) {
break
}
switch hdr.Type {
case unix.NLMSG_DONE:
remain = []byte{}
case unix.RTM_NEWLINK:
info := *(*unix.IfInfomsg)(unsafe.Pointer(&remain[unix.SizeofNlMsghdr]))
remain = remain[hdr.Len:]
2017-08-17 00:25:39 +02:00
2017-08-17 12:58:18 +02:00
if info.Index != tun.index {
// not our interface
continue
}
2017-08-17 00:25:39 +02:00
if info.Flags&unix.IFF_RUNNING != 0 {
2018-02-11 18:55:30 +01:00
tun.events <- TUNEventUp
2017-08-17 00:25:39 +02:00
}
if info.Flags&unix.IFF_RUNNING == 0 {
2018-02-11 18:55:30 +01:00
tun.events <- TUNEventDown
2017-08-17 00:25:39 +02:00
}
2018-02-11 18:55:30 +01:00
tun.events <- TUNEventMTUUpdate
2017-08-17 00:25:39 +02:00
default:
remain = remain[hdr.Len:]
}
}
}
2017-06-04 21:48:15 +02:00
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) isUp() (bool, error) {
2017-08-04 16:15:53 +02:00
inter, err := net.InterfaceByName(tun.name)
return inter.Flags&net.FlagUp != 0, err
}
func getIFIndex(name string) (int32, error) {
fd, err := unix.Socket(
2017-08-17 00:25:39 +02:00
unix.AF_INET,
unix.SOCK_DGRAM,
0,
)
if err != nil {
return 0, err
}
defer unix.Close(fd)
2018-02-13 16:43:07 +01:00
var ifr [ifReqSize]byte
2017-08-17 00:25:39 +02:00
copy(ifr[:], name)
_, _, errno := unix.Syscall(
unix.SYS_IOCTL,
uintptr(fd),
uintptr(unix.SIOCGIFINDEX),
uintptr(unsafe.Pointer(&ifr[0])),
)
if errno != 0 {
return 0, errno
}
2018-05-23 02:10:54 +02:00
return *(*int32)(unsafe.Pointer(&ifr[unix.IFNAMSIZ])), nil
2017-08-17 00:25:39 +02:00
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) setMTU(n int) error {
2017-07-15 16:27:59 +02:00
// open datagram socket
fd, err := unix.Socket(
unix.AF_INET,
unix.SOCK_DGRAM,
2017-07-15 16:27:59 +02:00
0,
)
if err != nil {
return err
}
defer unix.Close(fd)
2017-07-18 14:15:29 +02:00
2017-07-15 16:27:59 +02:00
// do ioctl call
2018-02-13 16:43:07 +01:00
var ifr [ifReqSize]byte
2017-07-15 16:27:59 +02:00
copy(ifr[:], tun.name)
2018-05-23 02:10:54 +02:00
*(*uint32)(unsafe.Pointer(&ifr[unix.IFNAMSIZ])) = uint32(n)
_, _, errno := unix.Syscall(
unix.SYS_IOCTL,
2017-07-15 16:27:59 +02:00
uintptr(fd),
uintptr(unix.SIOCSIFMTU),
2017-07-15 16:27:59 +02:00
uintptr(unsafe.Pointer(&ifr[0])),
)
if errno != 0 {
2018-05-21 17:27:18 +02:00
return errors.New("failed to set MTU of TUN device")
2017-07-15 16:27:59 +02:00
}
return nil
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) MTU() (int, error) {
2017-07-11 22:48:58 +02:00
// open datagram socket
fd, err := unix.Socket(
unix.AF_INET,
unix.SOCK_DGRAM,
2017-07-11 22:48:58 +02:00
0,
)
if err != nil {
return 0, err
}
defer unix.Close(fd)
2017-07-18 14:15:29 +02:00
2017-07-11 22:48:58 +02:00
// do ioctl call
2018-02-13 16:43:07 +01:00
var ifr [ifReqSize]byte
2017-07-11 22:48:58 +02:00
copy(ifr[:], tun.name)
_, _, errno := unix.Syscall(
unix.SYS_IOCTL,
2017-07-11 22:48:58 +02:00
uintptr(fd),
uintptr(unix.SIOCGIFMTU),
2017-07-11 22:48:58 +02:00
uintptr(unsafe.Pointer(&ifr[0])),
)
if errno != 0 {
2018-05-21 17:27:18 +02:00
return 0, errors.New("failed to get MTU of TUN device: " + strconv.FormatInt(int64(errno), 10))
2017-07-11 22:48:58 +02:00
}
2018-05-23 02:10:54 +02:00
return int(*(*int32)(unsafe.Pointer(&ifr[unix.IFNAMSIZ]))), nil
2017-06-04 21:48:15 +02:00
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) Name() (string, error) {
2018-04-18 16:39:14 +02:00
var ifr [ifReqSize]byte
_, _, errno := unix.Syscall(
unix.SYS_IOCTL,
tun.fd,
uintptr(unix.TUNGETIFF),
uintptr(unsafe.Pointer(&ifr[0])),
)
2018-04-18 16:39:14 +02:00
if errno != 0 {
2018-05-21 17:27:18 +02:00
return "", errors.New("failed to get name of TUN device: " + strconv.FormatInt(int64(errno), 10))
2018-04-18 16:39:14 +02:00
}
2018-05-05 02:47:35 +02:00
nullStr := ifr[:]
i := bytes.IndexByte(nullStr, 0)
if i != -1 {
nullStr = nullStr[:i]
}
tun.name = string(nullStr)
2018-04-18 16:39:14 +02:00
return tun.name, nil
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) Write(buff []byte, offset int) (int, error) {
2017-12-04 21:39:06 +01:00
2018-02-28 12:40:56 +01:00
if tun.nopi {
buff = buff[offset:]
2017-12-04 21:39:06 +01:00
} else {
2018-02-28 12:40:56 +01:00
// reserve space for header
buff = buff[offset-4:]
// add packet information header
buff[0] = 0x00
buff[1] = 0x00
2018-04-20 05:30:22 +02:00
if buff[4]>>4 == ipv6.Version {
2018-02-28 12:40:56 +01:00
buff[2] = 0x86
buff[3] = 0xdd
} else {
buff[2] = 0x08
buff[3] = 0x00
}
2017-12-04 21:39:06 +01:00
}
// write
2018-10-17 21:26:53 +02:00
return tun.tunFile.Write(buff)
2017-06-04 21:48:15 +02:00
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) doRead(buff []byte, offset int) (int, error) {
2017-08-17 00:25:39 +02:00
select {
case err := <-tun.errors:
return 0, err
default:
2018-02-28 12:40:56 +01:00
if tun.nopi {
2018-10-17 21:26:53 +02:00
return tun.tunFile.Read(buff[offset:])
2018-02-28 12:40:56 +01:00
} else {
buff := buff[offset-4:]
2018-10-17 21:26:53 +02:00
n, err := tun.tunFile.Read(buff[:])
2018-02-28 12:40:56 +01:00
if n < 4 {
return 0, err
}
return n - 4, err
2017-12-04 21:39:06 +01:00
}
2017-08-17 00:25:39 +02:00
}
2017-06-04 21:48:15 +02:00
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) Read(buff []byte, offset int) (int, error) {
for {
n, err := tun.doRead(buff, offset)
if err == nil || !rwcancel.RetryAfterError(err) {
return n, err
}
if !tun.fdCancel.ReadyRead() {
return 0, errors.New("tun device closed")
}
}
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) Events() chan TUNEvent {
2017-08-07 15:25:04 +02:00
return tun.events
}
2019-03-01 00:05:57 +01:00
func (tun *NativeTun) Close() error {
2018-05-14 14:08:03 +02:00
var err1 error
if tun.statusListenersShutdown != nil {
close(tun.statusListenersShutdown)
if tun.netlinkCancel != nil {
err1 = tun.netlinkCancel.Cancel()
}
} else if tun.events != nil {
close(tun.events)
2018-05-14 14:08:03 +02:00
}
2018-10-17 21:26:53 +02:00
err2 := tun.tunFile.Close()
err3 := tun.fdCancel.Cancel()
2018-05-14 02:14:33 +02:00
if err1 != nil {
return err1
}
if err2 != nil {
return err2
}
return err3
2017-08-07 15:25:04 +02:00
}
2018-05-23 02:10:54 +02:00
func CreateTUN(name string, mtu int) (TUNDevice, error) {
nfd, err := unix.Open(cloneDevicePath, os.O_RDWR, 0)
if err != nil {
return nil, err
}
fd := os.NewFile(uintptr(nfd), cloneDevicePath)
2017-06-04 21:48:15 +02:00
if err != nil {
return nil, err
}
2017-07-15 16:27:59 +02:00
// create new device
2018-02-13 16:43:07 +01:00
var ifr [ifReqSize]byte
var flags uint16 = unix.IFF_TUN // | unix.IFF_NO_PI (disabled for TUN status hack)
2017-06-04 21:48:15 +02:00
nameBytes := []byte(name)
if len(nameBytes) >= unix.IFNAMSIZ {
2018-05-14 02:14:33 +02:00
return nil, errors.New("interface name too long")
2017-06-04 21:48:15 +02:00
}
copy(ifr[:], nameBytes)
2018-05-23 02:10:54 +02:00
*(*uint16)(unsafe.Pointer(&ifr[unix.IFNAMSIZ])) = flags
2017-06-04 21:48:15 +02:00
_, _, errno := unix.Syscall(
unix.SYS_IOCTL,
fd.Fd(),
uintptr(unix.TUNSETIFF),
uintptr(unsafe.Pointer(&ifr[0])),
)
2017-06-04 21:48:15 +02:00
if errno != 0 {
2017-08-17 00:25:39 +02:00
return nil, errno
2017-06-04 21:48:15 +02:00
}
return CreateTUNFromFile(fd, mtu)
}
2017-07-11 22:48:58 +02:00
2018-05-23 02:10:54 +02:00
func CreateTUNFromFile(file *os.File, mtu int) (TUNDevice, error) {
2019-03-01 00:05:57 +01:00
tun := &NativeTun{
2018-10-17 21:26:53 +02:00
tunFile: file,
fd: file.Fd(),
2018-05-14 03:43:56 +02:00
events: make(chan TUNEvent, 5),
errors: make(chan error, 5),
2018-05-14 04:19:25 +02:00
statusListenersShutdown: make(chan struct{}),
2018-10-17 21:26:53 +02:00
nopi: false,
2017-07-15 16:27:59 +02:00
}
var err error
tun.fdCancel, err = rwcancel.NewRWCancel(int(tun.fd))
if err != nil {
return nil, err
}
2018-05-14 12:27:29 +02:00
_, err = tun.Name()
if err != nil {
return nil, err
}
2017-07-15 16:27:59 +02:00
2017-08-17 12:58:18 +02:00
// start event listener
2017-08-17 00:25:39 +02:00
2018-05-14 12:27:29 +02:00
tun.index, err = getIFIndex(tun.name)
2017-08-17 00:25:39 +02:00
if err != nil {
return nil, err
}
2018-05-14 12:27:29 +02:00
tun.netlinkSock, err = createNetlinkSocket()
if err != nil {
2018-05-14 14:08:03 +02:00
return nil, err
}
tun.netlinkCancel, err = rwcancel.NewRWCancel(tun.netlinkSock)
if err != nil {
unix.Close(tun.netlinkSock)
2018-05-14 12:27:29 +02:00
return nil, err
}
2018-05-21 03:31:44 +02:00
tun.hackListenerClosed.Lock()
2018-05-23 02:10:54 +02:00
go tun.routineNetlinkListener()
go tun.routineHackListener() // cross namespace
2018-05-14 12:27:29 +02:00
2018-05-23 02:10:54 +02:00
err = tun.setMTU(mtu)
2018-05-14 02:14:33 +02:00
if err != nil {
unix.Close(tun.netlinkSock)
2018-05-14 02:14:33 +02:00
return nil, err
}
2018-05-14 12:27:29 +02:00
return tun, nil
2017-06-04 21:48:15 +02:00
}